CVE-2022-31164

Tovy is a a staff management system for Roblox groups. A vulnerability in versions prior to 0.7.51 allows users to log in as other users, including privileged users such as the other of the instance. The problem has been patched in version 0.7.51.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tovyblox:tovy:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:04

Type Values Removed Values Added
References () https://github.com/tovyblox/tovy/pull/63 - Patch, Third Party Advisory () https://github.com/tovyblox/tovy/pull/63 - Patch, Third Party Advisory
References () https://github.com/tovyblox/tovy/security/advisories/GHSA-j6f8-wh4v-jc37 - Third Party Advisory () https://github.com/tovyblox/tovy/security/advisories/GHSA-j6f8-wh4v-jc37 - Third Party Advisory

Information

Published : 2022-07-22 04:15

Updated : 2024-11-21 07:04


NVD link : CVE-2022-31164

Mitre link : CVE-2022-31164

CVE.ORG link : CVE-2022-31164


JSON object : View

Products Affected

tovyblox

  • tovy
CWE
CWE-287

Improper Authentication