PT-2022-16529 · Unknown · Ourphoto App

·

CVE-2022-24189

·

Published

2022-11-28

·

Updated

2022-12-01

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ourphoto App version 1.4.1
Description The issue concerns the improper implementation of the user token authorization header on the /apiv1/* API endpoints. This allows an attacker to bypass authorization and session management by removing the user token value, causing all requests to succeed. As a result, an attacker can make POST API calls with other users' unique identifiers, potentially enumerating information of all other end-users.
Recommendations For Ourphoto App version 1.4.1, consider temporarily disabling the /apiv1/* API endpoints until a proper fix is implemented to prevent unauthorized access. Additionally, restrict access to sensitive user information to minimize the risk of exploitation. Avoid using the user token authorization header in the affected API endpoints until the issue is resolved.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24189

Affected Products

Ourphoto App