Improper Input Validation Vulnerability in PocketMine-MP Server Software
CVE-2023-7332
7.1HIGH
What is CVE-2023-7332?
PocketMine-MP versions before 4.18.1 suffer from an input validation flaw during inventory transaction processing. This vulnerability allows a remote attacker, with a legitimate player session, to exploit the server by issuing commands to drop more items than are present in the player's hotbar. This can lead to a server crash, effectively causing a denial of service. Users are strongly advised to upgrade to version 4.18.1 or later to mitigate this risk.
Affected Version(s)
PocketMine-MP 0 < 4.18.1
