Skip to content
This repository has been archived by the owner on Jul 30, 2024. It is now read-only.

V1.1

Compare
Choose a tag to compare
@aniko33 aniko33 released this 23 Dec 23:58
· 13 commits to main since this release
37d347a

Version 1.1 📣

Exploit

This exploit allowed the attacker to connect with a client, for example Netcat: he entered the username and started sending unencrypted messages, the other clients tried to decrypt but without success crashing the application.

CVSS score

link

Value Score
CVSS Base Score 7.3
Impact Subscore 3.4
Exploitability Subscore 3.9
CVSS Temporal Score 6.8
CVSS Environmental Score 6.8
Modified Impact Subscore 3.4
Overall CVSS Score 6.8
Changelog
  • 💣 Vulnerability fixed (Denial of Service - PoC).
  • 🐛 Bug fixing.
Additions
  • ✔ Username check
  • 📜 Get username (/nick)