Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-55946— Playloom Engine Data Storage Vulnerability

Quick assessment

Affected
Quetrobits Playloom-Engine
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Playloom Engine是Quetro个人开发者的一款开源的高性能游戏开发引擎。旨在帮助开发者创建身临其境的 2D 和 3D 游戏。 Playloom Engine v0.0.1版本存在信息泄露漏洞,该漏洞源于存在与数据存储相关的安全问题,尤其是在使用协作功能时,攻击者可能会访问用户输入到软件中的个人信息。

AI Predicted 3.3 Difficulty: Easy EPSS 0.39% · P32

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-55946

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Playloom Engine Data Storage Vulnerability
Source: CVE Program / CVE List V5
Vulnerability Description
Playloom Engine is an open-source, high-performance game development engine. Engine Beta v0.0.1 has a security vulnerability related to data storage, specifically when using the collaboration features. When collaborating with another user, they may have access to personal information you have entered into the software. This poses a risk to user privacy. The maintainers of Playloom Engine have temporarily disabled the collaboration feature until a fix can be implemented. When Engine Beta v0.0.2 is released, it is expected to contain a patch addressing this issue. Users should refrain from using the collaboration feature in the meantime.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5
Vulnerability Title
Playloom Engine 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Playloom Engine是Quetro个人开发者的一款开源的高性能游戏开发引擎。旨在帮助开发者创建身临其境的 2D 和 3D 游戏。 Playloom Engine v0.0.1版本存在信息泄露漏洞,该漏洞源于存在与数据存储相关的安全问题,尤其是在使用协作功能时,攻击者可能会访问用户输入到软件中的个人信息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Quetrobits Playloom-Engine <= beta-v0.0.1 -

II. Public POCs for CVE-2024-55946

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-55946

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2024-55946

No comments yet


Leave a comment