CyberSec.Space Logo
Back to CVE Browser

CVE-2018-6651

HIGH
8.8
CVSS Severity Score
EPSS Score0.0860%
EPSS Percentile20.00th
PublishedFeb 5, 2018
Last ModifiedNov 21, 2024

Vulnerability Description

In the uncurl_ws_accept function in uncurl.c in uncurl before 0.07, as used in Parsec before 140-3, insufficient Origin header validation (accepting an arbitrary substring match) for WebSocket API requests allows remote attackers to bypass intended access restrictions. In Parsec, this means full control over the victim's computer.

Affected Platforms (CPE)

πŸ“¦
Uncurl Project

Uncurl

< 0.07
πŸ“¦
Parsecgaming

Parsec

< 140-3

References & Advisories

Related Vulnerabilities