← Back

Supersmart.me Walk Through

supersmart.me_-_walk_through

Vendor: Supersmart • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Supersmart
1Supersmart.me Walk Through
Jun 17, 2026
Aug 5, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
insert HTML / js code inside input how to get to the vulnerable input : Workers > worker nickname > inject in this input the code.
1Supersmart
1Supersmart.me Walk Through
Jun 17, 2026
Jul 21, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
It was possible to download all receipts without authentication. Must first access the API https://XXXX.supersmart.me/services/v4/customer/signin to get a TOKEN. Then you can then access the API that provides invoice ima...Show more
It was possible to download all receipts without authentication. Must first access the API https://XXXX.supersmart.me/services/v4/customer/signin to get a TOKEN. Then you can then access the API that provides invoice images based on the URL https://XXXX.supersmart.me/services/v4/invoiceImg?orderId=XXXXXShow less