Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j394-f827-96m2

Опубликовано: 06 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Supersmart.me - Walk Through Performing unauthorized actions on other customers. Supersmart.me has a product designed to conduct smart shopping in stores. The customer receives a coder (or using an Android application) to scan at the beginning of the purchase the QR CODE on the cart, and then all the products he wants to purchase. At the end of the purchase the customer can pay independently. During the research it was discovered that it is possible to reset another customer's cart without verification. Because the number of purchases is serial.

Supersmart.me - Walk Through Performing unauthorized actions on other customers. Supersmart.me has a product designed to conduct smart shopping in stores. The customer receives a coder (or using an Android application) to scan at the beginning of the purchase the QR CODE on the cart, and then all the products he wants to purchase. At the end of the purchase the customer can pay independently. During the research it was discovered that it is possible to reset another customer's cart without verification. Because the number of purchases is serial.

EPSS

Процентиль: 44%
0.00212
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
больше 3 лет назад

insert HTML / js code inside input how to get to the vulnerable input : Workers > worker nickname > inject in this input the code.

EPSS

Процентиль: 44%
0.00212
Низкий

7.5 High

CVSS3