CVE-2022-34768 – Supersmart.me – Walk Through Performing unauthorized actions on other customers. Supersmar …

Vuln ID: CVE-2022-34768

Published:  2022-08-05  16:15:14Z

Description: Supersmart.me – Walk Through Performing unauthorized actions on other customers. Supersmart.me has a product designed to conduct smart shopping in stores. The customer receives a coder (or using an Android application) to scan at the beginning of the purchase the QR CODE on the cart, and then all the products he wants to purchase. At the end of the purchase the customer can pay independently. During the research it was discovered that it is possible to reset another customer’s cart without verification. Because the number of purchases is serial.

Source: NVD.NIST.GOV

 


Date:

Categorie(s):

Tag(s):