SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-24189

Removing the value causes all requests to succeed, bypassing authorization and session management.

MEDIUM 6.5EPSS 0.51%

Does this matter?

Lower severity and a low EPSS score (0.51%). Track it; it rarely justifies an emergency change on its own.

Description

The user_token authorization header on the Ourphoto App version 1.4.1 /apiv1/* end-points is not implemented properly. Removing the value causes all requests to succeed, bypassing authorization and session management. The impact of this vulnerability allows an attacker POST api calls with other users unique identifiers and enumerate information of all other end-users.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS
0.51% probability · 42th percentile
CISA KEV
Not listed
Weakness
CWE-863
Affected
sz-fujia/ourphoto
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.