Back to search
CVE-2025-31488
Published: Apr 6, 2025
Modified: Apr 7, 2025
PUBLISHED
Description
Plain Craft Launcher (PCL) is a launcher for Minecraft. PCL allows users to use homepages provided by third parties. If controls such as WebBrowser are used in the homepage, WPF will use Internet Explorer to load the specified webpage. If the user uses a malicious homepage, the attacker can use IE background to access the specified webpage without knowing it. This vulnerability is fixed in 2.9.3.
| Vendor | Product | Versions |
|---|---|---|
Hex-Dragon | PCL2 | affected < 2.9.3 |
Weaknesses (CWE)
References
https://github.com/Hex-Dragon/PCL2/security/advisories/GHSA-wfpw-hfcp-9m73
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now