VulnerabilityModified
CVE-2023-47392
An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the carts of other users via sending a crafted add order request.
MEDIUM 5.3EPSS 0.50%
Does this matter?
Lower severity and a low EPSS score (0.50%). Track it; it rarely justifies an emergency change on its own.
Description
An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the carts of other users via sending a crafted add order request.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.50% probability · 41th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- mercedes-benz/mercedes me
- Source
- cve@mitre.org
References
- https://gist.github.com/wwwziziyu/d0ae135b8075f6db735d75135254e7a1Third Party Advisory
- https://gist.github.com/wwwziziyu/d0ae135b8075f6db735d75135254e7a1Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.