Description
Heptabase developed by Hepta Platforms has a Exposed Dangerous Method or Function vulnerability, allowing unauthenticated remote attackers to leverage social engineering techniques to trick a victim into opening or loading a malicious webpage within the Heptabase application, thereby gaining unauthorized access to camera and microphone permissions.
Problem types
CWE-749 Exposed dangerous method or function
Product status
Any version before 1.90.2
References
www.twcert.org.tw/tw/cp-132-10968-6be4c-1.html
www.twcert.org.tw/en/cp-139-10967-4947d-2.html