PT-2025-9706 · Maharashtra State Electricity Distribution Company Limited · Maharashtra State Electricity Distribution Company Limited Mahavitran Ios Application

Tejas Nitin Pingulkar

·

Publicado

2025-03-04

·

Atualizado

2025-03-21

·

CVE-2021-41719

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Maharashtra State Electricity Distribution Company Limited Mahavitran IOS Application version 16.1
Description The issue concerns the Maharashtra State Electricity Distribution Company Limited Mahavitran IOS Application, which uses the GET method to process requests containing sensitive information, such as user account name and password. This can lead to exposure of the sensitive information through the browser's history, referrers, web logs, and other sources.
Recommendations For version 16.1, consider modifying the application to use a more secure method, such as the POST method, to process requests containing sensitive information, and ensure that sensitive data like user account name and password are properly encrypted and protected. As a temporary workaround, restrict access to the application's history and referrers to minimize the risk of sensitive information exposure.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2021-41719

Produtos afetados

Maharashtra State Electricity Distribution Company Limited Mahavitran Ios Application