PT-2022-25542 · Ocomon · Ocomon

·

CVE-2022-40798

·

Published

2022-10-19

·

Updated

2025-05-08

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OcoMon version 4.0RC1
Description The issue allows for Incorrect Access Control, enabling an attacker to obtain a user's real email address by sending a specific request. By sending the same request with the correct email, it is possible to take over the account.
Recommendations For OcoMon version 4.0RC1, consider restricting access to sensitive user information, such as email addresses, until a fix is available. As a temporary workaround, limit the ability to send requests that can lead to account takeover.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-40798

Affected Products

Ocomon