CVE-2018-7295
PoC —CVSS 3.0
8.1 high
EPSS
<1%p36
Published
()
Modified
Description
ffxivlauncher.exe in Square Enix Final Fantasy XIV 4.21 and 4.25 on Windows is affected by Improper Enforcement of Message Integrity During Transmission in a Communication Channel, allowing a man-in-the-middle attacker to steal user credentials because a session retrieves global.js via http before proceeding to use https. This is fixed in Patch 4.3.
- Vendors
- square-enix
- Products
- final fantasy xiv
- Weakness
- CWE-924
- Vector
- CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.