CVE-2022-30628 is an authentication bypass vulnerability affecting SuperSmart's supersmart.me_walk_through product, allowing unauthorized access to all customer receipts. An attacker could first obtain a token via the sign-in API and then use it to download invoice images by manipulating the orderId parameter. Rated with a CVSS score of 5.5 (Medium), this vulnerability has a low attack complexity and could lead to high confidentiality impact, as it allows access to sensitive customer data. There is no evidence of active exploitation, and no public exploit code or significant community discussion has been observed for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:supersmart:supersmart.me_-_walk_through:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.