PT-2023-18852 · Selfwealth · Selfwealth Ios Mobile App

L00Neyhacker

·

Publicado

2023-02-01

·

Atualizado

2023-02-08

·

CVE-2023-23132

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Selfwealth iOS mobile App version 3.3.1
Description The issue concerns the disclosure of sensitive keys. Specifically, the application reveals hardcoded API keys.
Recommendations For Selfwealth iOS mobile App version 3.3.1, consider restricting access to the API endpoints that utilize the hardcoded keys until a patch is available. As a temporary workaround, avoid using the affected API endpoints that expose the sensitive information. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-23132

Produtos afetados

Selfwealth Ios Mobile App