Vulnerabilities > CVE-2022-30628 - Unspecified vulnerability in Supersmart Supersmart.Me - Walk Through
Attack vector
LOCAL Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
It was possible to download all receipts without authentication. Must first access the API https://XXXX.supersmart.me/services/v4/customer/signin to get a TOKEN. Then you can then access the API that provides invoice images based on the URL https://XXXX.supersmart.me/services/v4/invoiceImg?orderId=XXXXX
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |