Lucene search

K
cvelistINCDCVELIST:CVE-2022-34774
HistoryAug 22, 2022 - 2:41 p.m.

CVE-2022-34774 Tabit - Arbitrary account modification

2022-08-2214:41:59
INCD
www.cve.org
5
cve-2022-34774
tabit
arbitrary account modification
loyalty program
account takeover
endpoint vulnerability
personal details

CVSS3

6.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

AI Score

6.5

Confidence

High

EPSS

0.001

Percentile

31.3%

Tabit - Arbitrary account modification. One of the endpoints mapped by the tiny URL, was a page where an adversary can modify personal details, such as email addresses and phone numbers of a specific user in a restaurant’s loyalty program. Possibly allowing account takeover (the mail can be used to reset password).

CNA Affected

[
  {
    "product": "Tabit",
    "vendor": "Tabit",
    "versions": [
      {
        "lessThan": "3.27.0*",
        "status": "affected",
        "version": "3.27.0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

6.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

AI Score

6.5

Confidence

High

EPSS

0.001

Percentile

31.3%

Related for CVELIST:CVE-2022-34774