Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-10017 | Plain Craft Launcher (PCL) is a launcher for Minecraft. PCL allows users to use homepages provided by third parties. If controls such as WebBrowser are used in the homepage, WPF will use Internet Explorer to load the specified webpage. If the user uses a malicious homepage, the attacker can use IE background to access the specified webpage without knowing it. This vulnerability is fixed in 2.9.3. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 07 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 06 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Plain Craft Launcher (PCL) is a launcher for Minecraft. PCL allows users to use homepages provided by third parties. If controls such as WebBrowser are used in the homepage, WPF will use Internet Explorer to load the specified webpage. If the user uses a malicious homepage, the attacker can use IE background to access the specified webpage without knowing it. This vulnerability is fixed in 2.9.3. | |
| Title | Plain Craft Launcher's custom homepage can use Internet Explorer to load web pages with the help of controls such as WebBrowser | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-07T14:15:50.443Z
Reserved: 2025-03-28T13:36:51.298Z
Link: CVE-2025-31488
Updated: 2025-04-07T14:15:45.770Z
Status : Awaiting Analysis
Published: 2025-04-06T20:15:14.310
Modified: 2025-04-07T14:17:50.220
Link: CVE-2025-31488
No data.
OpenCVE Enrichment
No data.
EUVD