PT-2019-13125 · Momo · Momo
Momoa Guest
·
Publicado
2019-07-22
·
Atualizado
2020-08-24
·
CVE-2019-13099
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Momo application version 2.1.9
Description
The issue allows a non-root user to access confidential information, including usernames, passwords, and access tokens, which are stored insecurely in cleartext on the system. This can be achieved by accessing Logcat.
Recommendations
For Momo application version 2.1.9, consider restricting access to Logcat to minimize the risk of exploitation until a secure method of storing sensitive information is implemented.
Exploit
Correção
Cleartext Storage of Sensitive Information
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Momo