rAthena SQL Injection Vulnerability in PartyBooking Component
Vulnerability
A SQL injection vulnerability has been identified in the rAthena MMORPG server, specifically in versions prior to commit 0d89ae0. The issue arises in the PartyBooking component, where the 'WorldName' parameter is not properly sanitized, allowing for malicious SQL queries to be executed. This vulnerability has been rated critical, with a CVSS score of 9.1.
Impact
Exploitation of this vulnerability allows for SQL injection, where an attacker can manipulate SQL queries to the database. This could lead to unauthorized data access, data manipulation, or in some cases, executing administrative operations on the database.
Remediation
Users can update to rAthena version 0d89ae0 or later to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
