PreMiD 2.2.0 allows unintended access via the websocket transport. An attacker can receive events from a socket and emit events to a socket, potentially interfering with a victim's "now playing" status on Discord.
References
Link | Resource |
---|---|
https://github.com/PreMiD/PreMiD/pull/791 | Patch Third Party Advisory |
https://github.com/PreMiD/PreMiD/issues/790 | Exploit Issue Tracking Patch Third Party Advisory |
Configurations
Information
Published : 2022-02-20 13:15
Updated : 2022-07-12 10:42
NVD link : CVE-2021-46701
Mitre link : CVE-2021-46701
JSON object : View
CWE
CWE-346
Origin Validation Error
Products Affected
premid
- premid