Files
CVEs-PoC/2022/CVE-2022-24190.md
T
2024-06-18 02:51:15 +02:00

879 B

CVE-2022-24190

Description

The /device/acceptBind end-point for Ourphoto App version 1.4.1 does not require authentication or authorization. The user_token header is not implemented or present on this end-point. An attacker can send a request to bind their account to any users picture frame, then send a POST request to accept their own bind request, without the end-users approval or interaction.

POC

Reference

Github

No PoCs found on GitHub currently.