玩嘉电竞入口官方登录

Dec 30, 2020

  • Risk: medium
  • CVSS v3 Base Score: 4.3
  • CVSS v3 Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
  • CWE ID: CWE-352
  • CWE Name: Cross-Site Request Forgery (CSRF)

Description

The CSRF token was not properly checked on cookie authenticated requests against the ocs api.

Affected

  • 玩嘉电竞下载注册/core version < 10.6 (CVE-2020-28644)

Action taken

We fixed the CSRF token check.

Acknowledgment

Thanks to Alessandro Groppo – Hacktive Security s.r.l.

英雄联盟竞猜数据直播正规 英雄联盟竞猜查询决赛 英雄联盟竞猜数据抽注 英雄联盟竞猜入口手机版 大圣电竞(重庆)投注排名 VG电子比分手机版电脑版