Supersmart.me Walk Through
by Supersmart
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-34768 | Med | 0.42 | 6.5 | 0.00 | Aug 5, 2022 | insert HTML / js code inside input how to get to the vulnerable input : Workers > worker nickname > inject in this input the code. | ||
| CVE-2022-30628 | Med | 0.31 | 4.8 | 0.00 | Jul 21, 2022 | It was possible to download all receipts without authentication. Must first access the API https://XXXX.supersmart.me/services/v4/customer/signin to get a TOKEN. Then you can then access the API that provides invoice images based on the URL https://XXXX.supersmart.me/services/v4/… |
- risk 0.42cvss 6.5epss 0.00
insert HTML / js code inside input how to get to the vulnerable input : Workers > worker nickname > inject in this input the code.
- risk 0.31cvss 4.8epss 0.00
It was possible to download all receipts without authentication. Must first access the API https://XXXX.supersmart.me/services/v4/customer/signin to get a TOKEN. Then you can then access the API that provides invoice images based on the URL https://XXXX.supersmart.me/services/v4/…