Unauthorized updates to extended_info properties in /store/ajaxpackagesave
High
V
Valve
Submitted None
Team Summary
Official summary from Valve
Due to incorrectly-implemented access control, partners were able to set the "extended_info" value on their own packages. This in turn enabled other security-impacting issues such as the ability to create externally-grantable and other special package types.
Actions:
Reported by
lolcanyouexplainagainpleaselol
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Access Control - Generic