Loading HuntDB...

ISteamAssets gives partners control over unrelated community market transactions

High
V
Valve
Submitted None

Team Summary

Official summary from Valve

ISteamAssets APIs would check that the key parameter used was a partner key with access to the appid specified, but then would ignore the passed in appid and would operate on app 753 regardless. This allowed anyone with a partner key to make changes to Steam economy items, like trading cards, and also could be used to reverse wallet fund spending on the Steam Community Market.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Access Control - Generic