logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2022-24189

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2022-24189

Description:
The user_token authorization header on the Ourphoto App version 1.4.1 /apiv1/* end-points is not implemented properly. Removing the value causes all requests to succeed, bypassing authorization and session management. The impact of this vulnerability allows an attacker POST api calls with other users unique identifiers and enumerate information of all other end-users.
Last updated date:
12/01/2022
Type:
exploit
Confidence:
HIGH
Date of publishing:
12/01/2022
Reference url to background

https://www.scrawledsecurityblog.com/2022/11/automating-unsolicited-richard-pics.html

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy