Sz-fujia

Ourphoto

4 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.34%
  • Veröffentlicht 28.11.2022 22:15:10
  • Zuletzt bearbeitet 29.04.2025 14:15:18

The user_id and device_id on the Ourphoto App version 1.4.1 /device/* end-points both suffer from insecure direct object reference vulnerabilities. Other end-users user_id and device_id values can be enumerated by incrementing or decrementing id numb...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 28.11.2022 22:15:10
  • Zuletzt bearbeitet 29.04.2025 14:15:19

The /device/signin end-point for the Ourphoto App version 1.4.1 discloses clear-text password information for functionality within the picture frame devices. The deviceVideoCallPassword and mqttPassword are returned in clear-text. The lack of session...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 28.11.2022 22:15:10
  • Zuletzt bearbeitet 29.04.2025 14:15:20

The user_token authorization header on the Ourphoto App version 1.4.1 /apiv1/* end-points is not implemented properly. Removing the value causes all requests to succeed, bypassing authorization and session management. The impact of this vulnerability...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 28.11.2022 22:15:10
  • Zuletzt bearbeitet 29.04.2025 14:15:20

The /device/acceptBind end-point for Ourphoto App version 1.4.1 does not require authentication or authorization. The user_token header is not implemented or present on this end-point. An attacker can send a request to bind their account to any users...