WorldClient.dll in Alt-N MDaemon and WorldClient 8.1.3 trusts a Session parameter that contains a randomly generated session ID that is associated with a username, which allows remote attackers to perform actions as other users by guessing or sniffing the random value.
Software | From | Fixed in |
---|---|---|
alt-n / mdaemon | 8.1.3 | 8.1.3.x |
alt-n / worldclient | 8.1.3 | 8.1.3.x |