The leakage of the client secret in VISION MEAT WORKS TrackDiner10/10_mc Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://github.com/syz913/CVE-reports/blob/main/CVE-2023-39734.md | exploit |
https://liff.line.me/1660679145-eMKgg4rJ | vendor advisory |