CVE-2022-36539

WeDayCare B.V Ouderapp before v1.1.22 allows attackers to alter the ID value within intercepted calls to gain access to data of other parents and children.
References
Link Resource
https://apps.apple.com/nl/app/eigen-wijzer-ouderapp/id1331059326 Product Release Notes Third Party Advisory
https://github.com/Fopje/CVE-2022-36539 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:eigen\&wijzer_ouderapp_project:eigen\&wijzer_ouderapp:*:*:*:*:*:iphone_os:*:*

History

12 Sep 2022, 19:36

Type Values Removed Values Added
CWE CWE-639
CPE cpe:2.3:a:eigen\&wijzer_ouderapp_project:eigen\&wijzer_ouderapp:*:*:*:*:*:iphone_os:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References (MISC) https://github.com/Fopje/CVE-2022-36539 - (MISC) https://github.com/Fopje/CVE-2022-36539 - Exploit, Third Party Advisory
References (MISC) https://apps.apple.com/nl/app/eigen-wijzer-ouderapp/id1331059326 - (MISC) https://apps.apple.com/nl/app/eigen-wijzer-ouderapp/id1331059326 - Product, Release Notes, Third Party Advisory

07 Sep 2022, 17:48

Type Values Removed Values Added
New CVE

Information

Published : 2022-09-07 17:15

Updated : 2024-02-04 22:51


NVD link : CVE-2022-36539

Mitre link : CVE-2022-36539

CVE.ORG link : CVE-2022-36539


JSON object : View

Products Affected

eigen\&wijzer_ouderapp_project

  • eigen\&wijzer_ouderapp
CWE
CWE-639

Authorization Bypass Through User-Controlled Key