Lucene search

K
cveMitreCVE-2023-36123
HistoryOct 07, 2023 - 12:15 a.m.

CVE-2023-36123

2023-10-0700:15:11
CWE-22
mitre
web.nvd.nist.gov
36
cve-2023-36123
directory traversal
hex-dragon plain craft launcher 2
alpha 1.3.9
vulnerability
local attackers
arbitrary code
sensitive information
nvd

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

9.9%

Directory Traversal vulnerability in Hex-Dragon Plain Craft Launcher 2 version Alpha 1.3.9, allows local attackers to execute arbitrary code and gain sensitive information.

Affected configurations

Nvd
Node
plain_craft_launcher_2_projectplain_craft_launcher_2Match1.3.9alpha
VendorProductVersionCPE
plain_craft_launcher_2_projectplain_craft_launcher_21.3.9cpe:2.3:a:plain_craft_launcher_2_project:plain_craft_launcher_2:1.3.9:alpha:*:*:*:*:*:*

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

9.9%