CVE-2022-34774 is an arbitrary account modification vulnerability affecting Tabit's loyalty program software. An unauthenticated attacker could exploit an exposed endpoint to alter personal details like email addresses and phone numbers for specific users, potentially leading to account takeover through password resets. With a CVSS score of 5.3 (Medium), this vulnerability requires no user interaction or privileges, making it easily exploitable. While no public exploits, Metasploit modules, or active exploitation have been observed, its low EPSS score and lack of community discussion suggest it is not currently a high-priority threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.27.0CPE matchmatch criteria | cpe:2.3:a:tabit:tabit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.