← back
CVE-2022-4879

Forged Alliance Forever Vote improper authorization

CVSS 4.6 MEDIUMEPSS 0.5%CWE-285
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.6EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
06 Jan 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability was found in Forged Alliance Forever up to 3746. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Vote Handler. The manipulation leads to improper authorization. Upgrading to version 3747 is able to address this issue. The patch is named 6880971bd3d73d942384aff62d53058c206ce644. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217555.
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →