CVE-2023-47392: Infoleak
Published Nov 22, 2023
·Updated
An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the carts of other users via sending a crafted add order request.
Affected Software
1 affected component
Mercedes-Benz Mercedes Me Iphone Os<=1.34.0
Event History
Nov 22, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-47392?
The severity of CVE-2023-47392 is medium with a severity value of 5.3.
2
What is the affected software for CVE-2023-47392?
The affected software for CVE-2023-47392 is Mercedes me iOS App version 1.34.0 and below.
3
What is the access control issue in CVE-2023-47392?
The access control issue in CVE-2023-47392 allows attackers to view the carts of other users.
4
How can attackers exploit CVE-2023-47392?
Attackers can exploit CVE-2023-47392 by sending a crafted add order request.
5
Is there a fix for CVE-2023-47392?
There is no specific fix mentioned in the provided information. It is recommended to update to a version above 1.34.0 or apply any security patches provided by the vendor.