PT-2022-22322 · Tabit · Tabit

Published

2022-08-22

·

Updated

2023-03-28

·

CVE-2022-34771

CVSS v3.1

5.5

Medium

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Tabit (affected versions not specified)
Description The issue allows an adversary to send messages on Tabit's behalf to anyone registered on the system. The resend OTP API receives parameters such as phone number and CustomMessage, which can be used to craft malicious messages to any user of the system. Additionally, the API may have template injection potential, as entering {{OTP}} in the custom message field formats it into an OTP.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2022-34771

Affected Products

Tabit