Filtered by vendor Ovaledge Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-30357 1 Ovaledge 1 Ovaledge 2024-10-25 9.8 Critical
OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is required.
CVE-2022-30355 1 Ovaledge 1 Ovaledge 2024-10-25 9.8 Critical
OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is required.