WeDayCare B.V Ouderapp before v1.1.22 allows attackers to alter the ID value within intercepted calls to gain access to data of other parents and children.
References
Link | Resource |
---|---|
https://apps.apple.com/nl/app/eigen-wijzer-ouderapp/id1331059326 | Product Release Notes Third Party Advisory |
https://github.com/Fopje/CVE-2022-36539 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-09-07 10:15
Updated : 2022-09-12 12:36
NVD link : CVE-2022-36539
Mitre link : CVE-2022-36539
JSON object : View
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
Products Affected
eigen\&wijzer_ouderapp_project
- eigen\&wijzer_ouderapp