CVE-2022-23543

CVSS V2 None CVSS V3 None
Description
Silverware Games is a social network where people can play games online. Users can attach URLs to YouTube videos, the site will generate related `<iframe>` when the post will be published. The handler has some sort of protection so non-YouTube links can't be posted, as well as HTML tags are being stripped. However, it was still possible to add custom HTML attributes (e.g. `onclick=alert("xss")`) to the `<iframe>'. This issue was fixed in the version `1.1.34` and does not require any extra actions from our members. There has been no evidence that this vulnerability was used by anyone at this time.
Overview
  • CVE ID
  • CVE-2022-23543
  • Assigner
  • security-advisories@github.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2022-12-19T22:15:10
  • Last Modified Date
  • 2022-12-27T18:57:57
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:silverwaregames:silverwaregames:*:*:*:*:*:*:*:* 1 OR 1.1.34
History
Created Old Value New Value Data Type Notes
2022-12-19 23:14:48 Added to TrackCVE
2022-12-20 03:15:27 2022-12-19T22:15:10.920 2022-12-19T22:15:10 CVE Published Date updated
2022-12-20 03:15:27 2022-12-20T02:47:33 CVE Modified Date updated
2022-12-20 03:15:27 Received Awaiting Analysis Vulnerability Status updated
2022-12-22 12:20:02 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2022-12-27 19:14:48 2022-12-27T18:57:57 CVE Modified Date updated
2022-12-27 19:14:49 Undergoing Analysis Analyzed Vulnerability Status updated
2022-12-27 19:14:49 Weakness Enumeration update
2022-12-27 19:14:49 CPE Information updated