漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Supersmart.me – Walk Through access to business information without authentication
Vulnerability Description
It was possible to download all receipts without authentication. Must first access the API https://XXXX.supersmart.me/services/v4/customer/signin to get a TOKEN. Then you can then access the API that provides invoice images based on the URL https://XXXX.supersmart.me/services/v4/invoiceImg?orderId=XXXXX
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Vulnerability Type
N/A
Vulnerability Title
Supersmart 安全漏洞
Vulnerability Description
Supersmart是以色列Supersmart公司的一种用于实体零售的人工智能自动结账。 Supersmart 存在安全漏洞,该漏洞源于无需身份验证即可访问业务信息。
CVSS Information
N/A
Vulnerability Type
N/A