PT-2025-9706 · Maharashtra State Electricity Distribution Company Limited · Maharashtra State Electricity Distribution Company Limited Mahavitran Ios Application
Tejas Nitin Pingulkar
·
Publicado
2025-03-04
·
Atualizado
2025-03-21
·
CVE-2021-41719
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Maharashtra State Electricity Distribution Company Limited Mahavitran IOS Application version 16.1
Description
The issue concerns the Maharashtra State Electricity Distribution Company Limited Mahavitran IOS Application, which uses the GET method to process requests containing sensitive information, such as
user account name and password. This can lead to exposure of the sensitive information through the browser's history, referrers, web logs, and other sources.Recommendations
For version 16.1, consider modifying the application to use a more secure method, such as the POST method, to process requests containing sensitive information, and ensure that sensitive data like
user account name and password are properly encrypted and protected. As a temporary workaround, restrict access to the application's history and referrers to minimize the risk of sensitive information exposure.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Maharashtra State Electricity Distribution Company Limited Mahavitran Ios Application