PT-2013-6221 · Zippyyum · Zippyyum Subway Ca Kiosk App
Daniel E. Wood
·
Published
2013-12-12
·
Updated
2013-12-20
·
CVE-2013-6986
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ZippyYum Subway CA Kiosk app version 3.4
Description
The issue concerns the use of cleartext storage in SQLite cache databases. This allows attackers to obtain sensitive information by reading data elements, such as password elements.
Recommendations
For ZippyYum Subway CA Kiosk app version 3.4, consider implementing secure storage mechanisms to protect sensitive data, such as encrypting the SQLite cache databases. As a temporary workaround, restrict access to the app's data storage to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zippyyum Subway Ca Kiosk App