CVE-2022-51014
MEDIUM6.5CVSS v3
—CVSS v2
—
EPSS (exploit probability)
CWE-248CWE
Description
PocketMine-MP before 4.0.7 contains an unhandled exception vulnerability in the ModalFormResponsePacket handler when processing malformed JSON from clients. Attackers can send specially crafted form response packets with invalid JSON to trigger an uncaught InvalidArgumentException, causing server crashes.
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected routers (0)
No routers currently mapped to this CVE in our database.