Vulnerabilities > CVE-2022-40798 - Unspecified vulnerability in Ocomon Project Ocomon 3.3/4.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
ocomon-project

Summary

OcoMon 4.0RC1 is vulnerable to Incorrect Access Control. Through a request the user can obtain the real email, sending the same request with correct email its possible to account takeover.

Vulnerable Configurations

Part Description Count
Application
Ocomon_Project
4