Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-15115

Опубликовано: 04 янв. 2026
Источник: nvd
CVSS3: 6.5
CVSS3: 9.8
EPSS Низкий

Описание

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authentication bypass vulnerability that allows unauthenticated attackers to access any user account by exploiting OAuth token validation flaws in the social login system. Attackers can send requests to /member/auth/thirdLogin with arbitrary Google IDs and phoneBrand parameters to obtain full session tokens and account access without proper OAuth verification.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:petlibro:petlibro:*:*:*:*:-:*:*:*
Версия до 1.7.31 (включая)

EPSS

Процентиль: 41%
0.00192
Низкий

6.5 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 6.5
github
около 1 месяца назад

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authentication bypass vulnerability that allows unauthenticated attackers to access any user account by exploiting OAuth token validation flaws in the social login system. Attackers can send requests to /member/auth/thirdLogin with arbitrary Google IDs and phoneBrand parameters to obtain full session tokens and account access without proper OAuth verification.

EPSS

Процентиль: 41%
0.00192
Низкий

6.5 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-862