Open q178666380 opened 7 years ago
Attacker can modify code,and open a edit gui in client side,then send edit result to server,but server side not check who send NBT update packet, just invoke update methd Advice: add permisson check to all packet in handleServerSide method
You might consider switching to the more recent fork of this plugin. NBTEdit has switched developers twice since David did this. https://github.com/Jay113355/NBTEdit/releases/
@q178666380 HELLO
Attacker can modify code,and open a edit gui in client side,then send edit result to server,but server side not check who send NBT update packet, just invoke update methd Advice: add permisson check to all packet in handleServerSide method