CVE Published: 21/07/2022 |
CVE Updated: 16/09/2024 |
CVE Year: 2022 Source: INCD |
Vendor: Supersmart.me |
Product: Supersmart.me – Walk Through Status : PUBLISHED
CVE-2022-30628 Description
It was possible to download all receipts without authentication. Must first access the API https://XXXX.supersmart.me/services/v4/customer/signin to get a TOKEN. Then you can then access the API that provides invoice images based on the URL https://XXXX.supersmart.me/services/v4/invoiceImg?orderId=XXXXX
Metrics
CVSS Version: 3.1 |
Base Score: 4.8 MEDIUM Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L