VYPR

Supersmart.me Walk Through

by Supersmart

CVEs (2)

  • CVE-2022-34768MedAug 5, 2022
    risk 0.42cvss 6.5epss 0.00

    insert HTML / js code inside input how to get to the vulnerable input : Workers > worker nickname > inject in this input the code.

  • CVE-2022-30628MedJul 21, 2022
    risk 0.31cvss 4.8epss 0.00

    It was possible to download all receipts without authentication. Must first access the API https://XXXX.supersmart.me/services/v4/customer/signin to get a TOKEN. Then you can then access the API that provides invoice images based on the URL https://XXXX.supersmart.me/services/v4/…