PT-2019-12519 · Rediff · Rediffmail
811Rishi
+1
·
Published
2019-05-09
·
Updated
2020-08-24
·
CVE-2019-11836
CVSS v3.1
4.6
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Rediffmail application version 2.2.6
Description
The issue concerns the storage of cleartext mail content in files, which persists even after a user logs out.
Recommendations
For version 2.2.6, consider clearing the application's data storage after each use to minimize the risk of exposing sensitive mail content. As a temporary workaround, restrict access to the device's file storage to prevent unauthorized access to the cleartext mail content.
Exploit
Fix
Missing Encryption of Sensitive Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rediffmail