Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-29101 | The /device/acceptBind end-point for Ourphoto App version 1.4.1 does not require authentication or authorization. The user_token header is not implemented or present on this end-point. An attacker can send a request to bind their account to any users picture frame, then send a POST request to accept their own bind request, without the end-users approval or interaction. |
Tue, 29 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-29T13:35:11.846Z
Reserved: 2022-01-31T00:00:00.000Z
Link: CVE-2022-24190
Updated: 2024-08-03T04:07:01.485Z
Status : Modified
Published: 2022-11-28T22:15:10.567
Modified: 2025-04-29T14:15:20.227
Link: CVE-2022-24190
No data.
OpenCVE Enrichment
No data.
EUVD