Executive brief
MobiAPParc is a mobile app that allows users to pay for parking in municipal car parks managed by Palma City Council. An attacker can bypass the password reset mechanism and reset passwords for any user account without proving they own the account, gaining full access to victims' parking payment accounts and potentially their payment methods and personal information.
Technical details
The vulnerability is a password reset authorization bypass caused by improper validation of the user_id parameter in the password recovery mechanism. The user_id parameter is predictable (numeric) and is not properly validated to ensure the requester owns the account they are attempting to reset. An attacker can manipulate this parameter to reset passwords for arbitrary user accounts over the network without authentication or user interaction. This allows complete account takeover and unauthorized modification of account data. The vendor (SMAP) has patched the vulnerability in the latest version of the app.
Affected products
- SMAP MobiAPParc iOS v0–v2.28; Android v0–v2.42
Timeline
- 2026-09-17: disclosed: Public disclosure via INCIBE-CERT advisory
- patched: Fixed in latest version of the app per vendor