ISteamAssets gives partners control over unrelated community market transactions
High
V
Valve
Submitted None
Team Summary
Official summary from Valve
ISteamAssets APIs would check that the key parameter used was a partner key with access to the appid specified, but then would ignore the passed in appid and would operate on app 753 regardless. This allowed anyone with a partner key to make changes to Steam economy items, like trading cards, and also could be used to reverse wallet fund spending on the Steam Community Market.
Actions:
Reported by
lolcanyouexplainagainpleaselol
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Access Control - Generic