Executive brief
The Assassin game by Gaudire, an interactive platform used for municipal events, contains a flaw that exposes sensitive participant information. An unauthorized person could access private contact details, including the email addresses and phone numbers of players, some of whom may be minors. This exposure poses a significant privacy risk and could lead to the misuse of personal data belonging to citizens and municipal users.
Technical details
The vulnerability is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The application's API fails to adequately protect sensitive fields, specifically exposing 'email' and 'telefon' (phone number) data without authentication. Additionally, the local database contains accessible sensitive information regarding municipal users and minors. An unauthenticated remote attacker can exploit these endpoints to harvest personal identifiable information (PII). As of the advisory date, there is no known patch or solution available.
Affected products
- Gaudire Assassin game last version
Timeline
- 2026-06-22: advisory: Advisory published by INCIBE-CERT
- 2026-06-22: disclosed