PT-2026-51317 · Gaudire · Assassin Game

CVE-2026-7165

·

Published

2026-06-22

·

Updated

2026-06-22

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description Multiple input validation issues exist in the '/addJugador' endpoint. The keyJugador and keyJugadorObjectiu parameters allow the modification of other users' information without authorization validation, enabling an authenticated attacker to alter any user's ID. The punts and numObjectiusEliminats fields lack proper validation, allowing arbitrary data entry to falsify game scores and obtain prizes. In the tokens field, administrative privileges can be self-assigned without server validation, leading to privilege escalation. Additionally, numeric fields accept excessively long values that can cause a system crash, resulting in a denial-of-service (DoS) state. Finally, the urlImatge parameter allows server-side requests to arbitrary URLs, which can be used to retrieve internal IP addresses, access internal services, read local files, and interact with third-party APIs.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7165

Affected Products

Assassin Game