Description
Tabit - Arbitrary account modification. One of the endpoints mapped by the tiny URL, was a page where an adversary can modify personal details, such as email addresses and phone numbers of a specific user in a restaurant's loyalty program. Possibly allowing account takeover (the mail can be used to reset password).
No analysis available yet.
Remediation
Vendor Solution
Update to version 3.27.0.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-37722 | Tabit - Arbitrary account modification. One of the endpoints mapped by the tiny URL, was a page where an adversary can modify personal details, such as email addresses and phone numbers of a specific user in a restaurant's loyalty program. Possibly allowing account takeover (the mail can be used to reset password). |
References
| Link | Providers |
|---|---|
| https://www.gov.il/en/departments/faq/cve_advisories |
|
History
No history.
Status: PUBLISHED
Assigner: INCD
Published:
Updated: 2024-09-17T03:55:05.773Z
Reserved: 2022-06-29T00:00:00.000Z
Link: CVE-2022-34774
No data.
Status : Modified
Published: 2022-08-22T15:15:16.293
Modified: 2024-11-21T07:10:09.550
Link: CVE-2022-34774
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD