PT-2026-51317 · Gaudire · Assassin Game
CVE-2026-7165
·
Published
2026-06-22
·
Updated
2026-06-22
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined (affected versions not specified)
Description
Multiple input validation issues exist in the '/addJugador' endpoint. The
keyJugador and keyJugadorObjectiu parameters allow the modification of other users' information without authorization validation, enabling an authenticated attacker to alter any user's ID. The punts and numObjectiusEliminats fields lack proper validation, allowing arbitrary data entry to falsify game scores and obtain prizes. In the tokens field, administrative privileges can be self-assigned without server validation, leading to privilege escalation. Additionally, numeric fields accept excessively long values that can cause a system crash, resulting in a denial-of-service (DoS) state. Finally, the urlImatge parameter allows server-side requests to arbitrary URLs, which can be used to retrieve internal IP addresses, access internal services, read local files, and interact with third-party APIs.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Assassin Game