CVE-2022-34768

CVE-2022-34768

Supersmart.me – Walk Through Performing unauthorized actions on other customers. Supersmart.me has a product designed to conduct smart shopping in stores. The customer receives a coder (or using an Android application) to scan at the beginning of the purchase the QR CODE on the cart, and then all the products he wants to purchase. At the end of the purchase the customer can pay independently. During the research it was discovered that it is possible to reset another customer’s cart without verification. Because the number of purchases is serial.

Source: CVE-2022-34768

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다