Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Yoshihito Sakai

Researcher fromBroadBand Security, Inc.
#26753of 53,633
9.5Total CVSS
Vulnerabilities · 2
Medium
2
PT-2024-28026
4.0
2024-07-01
Unknown · Piccoma App · CVE-2024-38480
**Name of the Vulnerable Software and Affected Versions** Piccoma App versions prior to 6.20.0 **Description** The issue concerns the use of a hard-coded API key for an external service in the Piccoma App, which could potentially allow a local attacker to obtain the API key. It is noted that the users of the app are not directly affected by this issue. **Recommendations** For versions prior to 6.20.0, update to version 6.20.0 or later to resolve the issue.
PT-2024-19877
5.5
2024-01-23
Unknown · Android Spoon · CVE-2024-23453
**Name of the Vulnerable Software and Affected Versions** Android Spoon application versions 7.11.1 through 8.6.0 **Description** The issue concerns the use of hard-coded credentials in the application, which could allow a local attacker to retrieve a hard-coded API key by reverse-engineering the application binary. This API key could then be used for unauthorized access to the associated service. **Recommendations** For Android Spoon application versions 7.11.1 through 8.6.0, consider removing or securely storing the hard-coded API key to prevent unauthorized access until a patch is available. As a temporary workaround, restrict access to the application's binary to minimize the risk of reverse-engineering.