WorldClient.dll in Alt-N MDaemon and WorldClient 8.1.3 trusts a Session parameter that contains a randomly generated session ID that is associated with a username, which allows remote attackers to perform actions as other users by guessing or sniffing the random value.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mdaemon | Alt-n | 8.1.3 (including) | 8.1.3 (including) |
Worldclient | Alt-n | 8.1.3 (including) | 8.1.3 (including) |