CVE-2022-24187

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/11/2022
Last modified:
29/04/2025

Description

The user_id and device_id on the Ourphoto App version 1.4.1 /device/* end-points both suffer from insecure direct object reference vulnerabilities. Other end-users user_id and device_id values can be enumerated by incrementing or decrementing id numbers. The impact of this vulnerability allows an attacker to discover sensitive information such as end-user email addresses, and their unique frame_token value of all other Ourphoto App end-users.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sz-fujia:ourphoto:1.4.1:*:*:*:*:*:*:*