9.8
CVSSv3

CVE-2023-39851

Published: 15/08/2023 Updated: 17/05/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9

Vulnerability Summary

webchess v1.0 exists to contain a SQL injection vulnerability via the $playerID parameter at mainmenu.php. NOTE: this is disputed by a third party who indicates that the playerID is a session variable controlled by the server, and thus cannot be used for exploitation.

Vulnerable Product Search on Vulmon Subscribe to Product

webchess project webchess 1.0