Webchess
Webchess Project · 3 CVEs
CVE-2023-39851
CRITICAL
webchess v1.0 was discovered to contain a SQL injection vulnerability via the $playerID parameter at mainmenu.php. NOTE…
Aug 15, 2023
CVE-2023-22959
HIGH
WebChess through 0.9.0 and 1.0.0.rc2 allows SQL injection: mainmenu.php, chess.php, and opponentspassword.php (txtFirst…
Jan 11, 2023
CVE-2019-20896
CRITICAL
WebChess 1.0 allows SQL injection via the messageFrom, gameID, opponent, messageID, or to parameter.
Jul 7, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2023-39851 | webchess v1.0 was discovered to contain a SQL injection vulnerability via the $playerID parameter at mainmenu.php. NOTE: this is disputed by a third party who… | CRITICAL | 0.85% | Aug 15, 2023 |
| CVE-2023-22959 | WebChess through 0.9.0 and 1.0.0.rc2 allows SQL injection: mainmenu.php, chess.php, and opponentspassword.php (txtFirstName, txtLastName). | HIGH | 13.70% | Jan 11, 2023 |
| CVE-2019-20896 | WebChess 1.0 allows SQL injection via the messageFrom, gameID, opponent, messageID, or to parameter. | CRITICAL | 0.99% | Jul 7, 2020 |
Showing 1 to 3 of 3 CVEs