PT-2019-12519 · Rediff · Rediffmail

811Rishi

+1

·

Published

2019-05-09

·

Updated

2020-08-24

·

CVE-2019-11836

CVSS v3.1

4.6

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Rediffmail application version 2.2.6
Description The issue concerns the storage of cleartext mail content in files, which persists even after a user logs out.
Recommendations For version 2.2.6, consider clearing the application's data storage after each use to minimize the risk of exposing sensitive mail content. As a temporary workaround, restrict access to the device's file storage to prevent unauthorized access to the cleartext mail content.

Exploit

Fix

Missing Encryption of Sensitive Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-11836

Affected Products

Rediffmail