CVE-2022-40798
19.10.2022, 02:15
OcoMon 4.0RC1 is vulnerable to Incorrect Access Control. Through a request the user can obtain the real email, sending the same request with correct email its possible to account takeover.Enginsight
Vendor | Product | Version |
---|---|---|
ocomon_project | ocomon | 𝑥 < 4.0 |
ocomon_project | ocomon | 4.0 |
ocomon_project | ocomon | 4.0:rc1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration