Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v3hv-r2rh-g9gw

Опубликовано: 22 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

It was possible to download all receipts without authentication. Must first access the API https://XXXX.supersmart.me/services/v4/customer/signin to get a TOKEN. Then you can then access the API that provides invoice images based on the URL https://XXXX.supersmart.me/services/v4/invoiceImg?orderId=XXXXX

It was possible to download all receipts without authentication. Must first access the API https://XXXX.supersmart.me/services/v4/customer/signin to get a TOKEN. Then you can then access the API that provides invoice images based on the URL https://XXXX.supersmart.me/services/v4/invoiceImg?orderId=XXXXX

EPSS

Процентиль: 14%
0.00046
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
nvd
больше 3 лет назад

It was possible to download all receipts without authentication. Must first access the API https://XXXX.supersmart.me/services/v4/customer/signin to get a TOKEN. Then you can then access the API that provides invoice images based on the URL https://XXXX.supersmart.me/services/v4/invoiceImg?orderId=XXXXX

EPSS

Процентиль: 14%
0.00046
Низкий

5.5 Medium

CVSS3