PT-2019-13125 · Momo · Momo

Momoa Guest

·

Published

2019-07-22

·

Updated

2020-08-24

·

CVE-2019-13099

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Momo application version 2.1.9
Description The issue allows a non-root user to access confidential information, including usernames, passwords, and access tokens, which are stored insecurely in cleartext on the system. This can be achieved by accessing Logcat.
Recommendations For Momo application version 2.1.9, consider restricting access to Logcat to minimize the risk of exploitation until a secure method of storing sensitive information is implemented.

Exploit

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-13099

Affected Products

Momo