An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the carts of other users via sending a crafted add order request.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://gist.github.com/wwwziziyu/d0ae135b8075f6db735d75135254e7a1 | third party advisory |