Known Vulnerabilities for products from Webchess Project
Listed below are 3 of the newest known vulnerabilities associated with the vendor "Webchess Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-39851 json | ** DISPUTED ** webchess v1.0 was discovered to contain a SQL injection vulnerability via the $playerID parameter at mainmenu.... | 9.8 - CRITICAL | 2023-08-15 | 2023-11-07 |
| CVE-2023-22959 json | WebChess through 0.9.0 and 1.0.0.rc2 allows SQL injection: mainmenu.php, chess.php, and opponentspassword.php (txtFirstName, ... | 8.8 - HIGH | 2023-01-11 | 2023-01-18 |
| CVE-2019-20896 json | WebChess 1.0 allows SQL injection via the messageFrom, gameID, opponent, messageID, or to parameter. | 9.8 - CRITICAL | 2020-07-07 | 2020-07-09 |
Known software with vulnerabilities from Webchess Project
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Webchess Project | Webchess | 1.0 |