7.5
CVSSv3

CVE-2022-24187

Published: 28/11/2022 Updated: 01/12/2022
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The user_id and device_id on the Ourphoto App version 1.4.1 /device/* end-points both suffer from insecure direct object reference vulnerabilities. Other end-users user_id and device_id values can be enumerated by incrementing or decrementing id numbers. The impact of this vulnerability allows an malicious user to discover sensitive information such as end-user email addresses, and their unique frame_token value of all other Ourphoto App end-users.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sz-fujia ourphoto 1.4.1