Remote Information Disclosure Vulnerability in Smart Things (prior to version 1.7.85.12) via Missing Caller Check

Remote Information Disclosure Vulnerability in Smart Things (prior to version 1.7.85.12) via Missing Caller Check

CVE-2022-30746 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface API.

Learn more about our Api Penetration Testing.