CVE-2023-40179
CVE-2023-40179 is a medium-severity vulnerability in Silverwaregames with a CVSS 3.x base score of 5.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-204.
Key facts
- Severity: Medium (CVSS 3.x base score 5.3)
- EPSS exploit prediction: 0% (31st percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-204
- Affected product: Silverwaregames
- Published:
- Last modified:
Description
Silverware Games is a premium social network where people can play games online. Prior to version 1.3.6, the Password Recovery form would throw an error if the specified email was not found in our database. It would only display the "Enter the code" form if the email is associated with a member of the site. Since version 1.3.6, the "Enter the code" form is always returned, showing the message "If the entered email is associated with an account, a code will be sent now". This change prevents potential violators from determining if our site has a user with the specified email.
Frequently asked questions
- What is CVE-2023-40179?
- Silverware Games is a premium social network where people can play games online. Prior to version 1.3.6, the Password Recovery form would throw an error if the specified email was not found in our database. It would only display the "Enter the code" form if the email is associated with a member of the site. Since version 1.3.6, the "Enter the code" form is always returned, showing the message "If the entered email is associated with an account, a code will be sent now". This change prevents potential violators from determining if our site has a user with the specified email.
- How severe is CVE-2023-40179?
- CVE-2023-40179 has a CVSS 3.x base score of 5.3, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is low, integrity none, and availability none.
- Is CVE-2023-40179 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (31st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2023-40179?
- CVE-2023-40179 affects Silverwaregames. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2023-40179?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2023-40179 published?
- CVE-2023-40179 was published on 2023-08-25 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:silverwaregames:silverwaregames:*:*:*:*:*:*:*:*
More vulnerabilities in Silverwaregames
- CVE-2022-23543 — Medium (CVSS 6.3): Silverware Games is a social network where people can play games online. Users can attach URLs to YouTube videos, the…
- CVE-2022-36072 — Medium (CVSS 5.9): SilverwareGames.io is a social network for users to play video games online. In version 1.1.8 and prior, due to an…
- CVE-2023-40182 — Low (CVSS 3.7): Silverware Games is a premium social network where people can play games online. When using the Recovery form, a…
- CVE-2023-29192 — Low (CVSS 2.7): SilverwareGames.io versions before 1.2.19 allow users with access to the game upload panel to edit download links for…
All CVEs affecting Silverwaregames →
Other CWE-204 vulnerabilities
- CVE-2018-25350 — Critical (CVSS 9.8): userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid…
- CVE-2026-15747 — Critical (CVSS 9.1): Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a…
- CVE-2026-69519 — High (CVSS 8.6): Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a…
- CVE-2025-5485 — High (CVSS 8.6): User names used to access the web management interface are limited to the device identifier, which is a numerical…
- CVE-2026-27462 — High (CVSS 7.5): Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for…
- CVE-2026-33419 — High (CVSS 7.5): MinIO is a high-performance object storage system. Prior to RELEASE.2026-03-17T21-25-16Z, MinIO AIStor's STS (Security…