Vulnerability Description
An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the carts of other users via sending a crafted add order request.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mercedes-Benz | Mercedes Me | <= 1.34.0 |
Related Weaknesses (CWE)
References
- https://gist.github.com/wwwziziyu/d0ae135b8075f6db735d75135254e7a1Third Party Advisory
- https://gist.github.com/wwwziziyu/d0ae135b8075f6db735d75135254e7a1Third Party Advisory
FAQ
What is CVE-2023-47392?
CVE-2023-47392 is a vulnerability with a CVSS score of 5.3 (MEDIUM). An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the carts of other users via sending a crafted add order request.
How severe is CVE-2023-47392?
CVE-2023-47392 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-47392?
Check the references section above for vendor advisories and patch information. Affected products include: Mercedes-Benz Mercedes Me.