PT-2023-18852 · Selfwealth · Selfwealth Ios Mobile App
L00Neyhacker
·
Publicado
2023-02-01
·
Atualizado
2023-02-08
·
CVE-2023-23132
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Selfwealth iOS mobile App version 3.3.1
Description
The issue concerns the disclosure of sensitive keys. Specifically, the application reveals hardcoded API keys.
Recommendations
For Selfwealth iOS mobile App version 3.3.1, consider restricting access to the API endpoints that utilize the hardcoded keys until a patch is available. As a temporary workaround, avoid using the affected API endpoints that expose the sensitive information. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Using Hardcoded Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Selfwealth Ios Mobile App