CVE-2022-40798

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/10/2022
Last modified:
08/05/2025

Description

OcoMon 4.0RC1 is vulnerable to Incorrect Access Control. Through a request the user can obtain the real email, sending the same request with correct email its possible to account takeover.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ocomon_project:ocomon:*:*:*:*:*:*:*:* 4.0 (excluding)
cpe:2.3:a:ocomon_project:ocomon:4.0:-:*:*:*:*:*:*
cpe:2.3:a:ocomon_project:ocomon:4.0:rc1:*:*:*:*:*:*