Loading HuntDB...

Unauthorized updates to extended_info properties in /store/ajaxpackagesave

High
V
Valve
Submitted None

Team Summary

Official summary from Valve

Due to incorrectly-implemented access control, partners were able to set the "extended_info" value on their own packages. This in turn enabled other security-impacting issues such as the ability to create externally-grantable and other special package types.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Access Control - Generic