Known Vulnerabilities for Ourphoto by Sz-fujia
Listed below are 4 of the newest known vulnerabilities associated with "Ourphoto" by "Sz-fujia".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-24190 json | The /device/acceptBind end-point for Ourphoto App version 1.4.1 does not require authentication or authorization. The user_to... | 7.5 - HIGH | 2022-11-28 | 2023-08-08 |
| CVE-2022-24189 json | The user_token authorization header on the Ourphoto App version 1.4.1 /apiv1/* end-points is not implemented properly. Removi... | 6.5 - MEDIUM | 2022-11-28 | 2022-12-01 |
| CVE-2022-24188 json | The /device/signin end-point for the Ourphoto App version 1.4.1 discloses clear-text password information for functionality w... | 7.5 - HIGH | 2022-11-28 | 2022-12-01 |
| CVE-2022-24187 json | The user_id and device_id on the Ourphoto App version 1.4.1 /device/* end-points both suffer from insecure direct object refe... | 7.5 - HIGH | 2022-11-28 | 2022-12-01 |