PT-2022-25542 · Ocomon · Ocomon

Ninj4C0D3R

·

Published

2022-10-19

·

Updated

2025-05-08

·

CVE-2022-40798

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OcoMon version 4.0RC1
Description The issue allows for Incorrect Access Control, enabling an attacker to obtain a user's real email address by sending a specific request. By sending the same request with the correct email, it is possible to take over the account.
Recommendations For OcoMon version 4.0RC1, consider restricting access to sensitive user information, such as email addresses, until a fix is available. As a temporary workaround, limit the ability to send requests that can lead to account takeover.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2022-40798

Affected Products

Ocomon