Known vulnerabilities

From Vintage Story Wiki
Revision as of 10:18, 20 June 2021 by Tyron (talk | contribs)

This is a list of known vulnerabilities across all Vintage Story services:

  • Wiki URL Content Spoofing
  • User email enumeration through the forget password function
  • Potential Broken Link Hijacking (we don't check if all linked sites redirect to registered sites)
  • Malicious site linking - we do not prevent users to link to a malicious site
  • EXIF data not filtered for certain image uploads