CVE-2022-34774
22.08.2022, 15:15
Tabit - Arbitrary account modification. One of the endpoints mapped by the tiny URL, was a page where an adversary can modify personal details, such as email addresses and phone numbers of a specific user in a restaurant's loyalty program. Possibly allowing account takeover (the mail can be used to reset password).Enginsight
Vendor | Product | Version |
---|---|---|
tabit | tabit | 𝑥 < 3.27.0 |
𝑥
= Vulnerable software versions