Vulnerabilities > CVE-2022-24190 - Missing Authorization vulnerability in Sz-Fujia Ourphoto 1.4.1
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
HIGH Availability impact
NONE Summary
The /device/acceptBind end-point for Ourphoto App version 1.4.1 does not require authentication or authorization. The user_token header is not implemented or present on this end-point. An attacker can send a request to bind their account to any users picture frame, then send a POST request to accept their own bind request, without the end-users approval or interaction.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |