PT-2019-12519 · Rediff · Rediffmail
811Rishi
+1
·
Publicado
2019-05-09
·
Atualizado
2020-08-24
·
CVE-2019-11836
CVSS v3.1
4.6
Média
| Vetor | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Rediffmail application version 2.2.6
Description
The issue concerns the storage of cleartext mail content in files, which persists even after a user logs out.
Recommendations
For version 2.2.6, consider clearing the application's data storage after each use to minimize the risk of exposing sensitive mail content. As a temporary workaround, restrict access to the device's file storage to prevent unauthorized access to the cleartext mail content.
Exploit
Correção
Missing Encryption of Sensitive Data
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Rediffmail