CVE-2026-25144

Published
View on NVD ↗
CVSS v3
5.3
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

Talishar is a fan-made Flesh and Blood project. A Stored XSS exists in the chat in-game system. The playerID parameter in SubmitChat.php and is saved without sanitization and executed whenever a user view the current page game. This vulnerability is fixed by 09dd00e5452e3cd998eb1406a88e5b0fa868e6b4.

Automated online client for the Flesh and Blood card game. There may be bugs, so the site should not be used as an indication of how the game works. Game interactions and rulings are the jurisdiction of LSS and judges.
GitHubGitHub
135