VYPR

Motp

by Changingtec

CVEs (2)

  • CVE-2021-44161HigDec 29, 2021
    risk 0.57cvss 8.8epss 0.01

    Changing MOTP (Mobile One Time Password) system’s specific function parameter has insufficient validation for user input. A attacker in local area network can perform SQL injection attack to read, modify or delete backend database without authentication.

  • CVE-2023-22901MedApr 27, 2023
    risk 0.32cvss 4.9epss 0.01

    ChangingTec MOTP system has a path traversal vulnerability. A remote attacker with administrator’s privilege can exploit this vulnerability to access arbitrary system files.