ZeroHour

CVE-2022-24189

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p42
Published
()
Modified
Description

The user_token authorization header on the Ourphoto App version 1.4.1 /apiv1/* end-points is not implemented properly. Removing the value causes all requests to succeed, bypassing authorization and session management. The impact of this vulnerability allows an attacker POST api calls with other users unique identifiers and enumerate information of all other end-users.

Vendors
sz-fujia
Products
ourphoto
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.