Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Issue: It is possible to access a restricted page without having to enter a password, when a different restricted page uses the same password. #1573

Open
Reispfannenfresser opened this issue Mar 31, 2024 · 0 comments
Labels

Comments

@Reispfannenfresser
Copy link

Describe the bug
Setting the same password on two separate restricted game pages, allows accessing both, once the password for one was entered.

To Reproduce

  1. Create two game pages.
  2. Go to both games settings and adjust the Restricted access settings, to allow accessing the page using a password.
  3. Set the same password for both games.
  4. Save the links to the games and the password somewhere for later use.
  5. Clear your browser data and go to the first of the two pages.
  6. You are asked to enter a password. Enter the password you set.
  7. Go to the second game page. You can access it without entering a password.

Expected behavior
I expected the second game page to ask me for a password also.

Desktop (please complete the following information):

  • OS: 5.15.150-1-MANJARO x86_64 GNU/Linux
  • Browser: Firefox
  • Version 124.0.1 (64-bit)

Additional context
This might only apply to games that were uploaded by the same account.
I have not tested what happens if the games were uploaded from different accounts.

Using the same password is not a good idea anyways and this may even be intended behavior.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant