Valve says it has fixed an HTML input issue in Counter-Strike 2 that was abused to insert images into games and obtain other players' IP addresses.
See also: IP Protection: Google Chrome feature hides IP addresses

Initially thought to be a more serious Cross Site Scripting (XSS) bug, which allows JavaScript on a client, it turned out to be simply an HTML embedding bug, which allows images to be inserted.
Counter-Strike 2 uses Valve, a user interface that heavily incorporates CSS, HTML, and JavaScript for layout design.
As part of the layout design, developers can configure input fields to accept HTML instead of converting it to plain text. If the field is enabled for HTML, any text entered will be rendered as HTML on output.
Today, Counter-Strike users began reporting that other users were exploiting an HTML injection vulnerability to insert images into the elimination voting panel. While the vulnerability was mostly abused for innocent fun, some people used it to obtain the IP addresses of other players in the game.
This was done using the tag <img> to open a remote IP logging script that caused the IP address to be logged for every player who saw the ban vote.
See also: Atlas VPN zero-day: Leaks users' IP addresses
These IP addresses can be used maliciously, such as to cause DDoS to disconnect players from the game.

This afternoon, Valve released a small 7MB update that reportedly fixes the vulnerability and causes any imported HTML to be converted to a regular alphanumeric. For example, after the update is installed, instead of the embedded HTML being rendered by the UI, it will simply be displayed as a string.
In 2019, a similar, but more serious, bug was discovered in Counter-Strike: Global Offensive that allowed HTML input via the eject function.
However, in that particular case, it could also be used to launch JavaScript, making it a much more critical XSS vulnerability, which could be used to execute commands remotely.
See also: Cisco reveals serious vulnerability affecting IP phones
An HTML injection bug has a significant impact on the security of websites and applications. When malicious HTML code is allowed to be injected into a web page, attackers can exploit this vulnerability to cause a variety of problems. This can include displaying misleading content, stealing users' personal information, performing malicious actions, or even compromising the system.
Additionally, the HTML injection bug can lead to cross-site scripting (XSS) attacks, in which malicious code is executed in the user's browser. This can have serious consequences, such as violating user privacy, malicious redirection to other websites, or even executing malicious commands on the computer .
Finally, the HTML injection bug can damage the reputation and credibility of a website or application. If users perceive that their website is vulnerable to HTML injection attacks, their trust may decrease and they may avoid using it. This can have negative consequences for the business or website owner, as it can lead to loss of revenue or customers.
Source: bleepingcomputer
