rAthena SQL Injection Vulnerability in PartyBooking Component

Vulnerability

A SQL injection vulnerability has been identified in the rAthena MMORPG server, specifically in versions prior to commit 0d89ae0. The issue arises in the PartyBooking component, where the 'WorldName' parameter is not properly sanitized, allowing for malicious SQL queries to be executed. This vulnerability has been rated critical, with a CVSS score of 9.1.

Impact

Exploitation of this vulnerability allows for SQL injection, where an attacker can manipulate SQL queries to the database. This could lead to unauthorized data access, data manipulation, or in some cases, executing administrative operations on the database.

Remediation

Users can update to rAthena version 0d89ae0 or later to address this vulnerability.

Added: Sep 9, 2025, 11:22 PM
Updated: Sep 9, 2025, 11:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
8.1
remediation
7.7
relevance
0.5
threat
3.2
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.