Known Vulnerabilities for Webchess by Webchess Project
Listed below are 3 of the newest known vulnerabilities associated with "Webchess" by "Webchess Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-39851 json | ** DISPUTED ** webchess v1.0 was discovered to contain a SQL injection vulnerability via the $playerID parameter at mainmenu.... | 9.8 - CRITICAL | 2023-08-15 | 2023-11-07 |
| CVE-2023-22959 json | WebChess through 0.9.0 and 1.0.0.rc2 allows SQL injection: mainmenu.php, chess.php, and opponentspassword.php (txtFirstName, ... | 8.8 - HIGH | 2023-01-11 | 2023-01-18 |
| CVE-2019-20896 json | WebChess 1.0 allows SQL injection via the messageFrom, gameID, opponent, messageID, or to parameter. | 9.8 - CRITICAL | 2020-07-07 | 2020-07-09 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Webchess Project | Webchess | 1.0 |