PT-2019-13125 · Momo · Momo
Momoa Guest
·
Published
2019-07-22
·
Updated
2020-08-24
·
CVE-2019-13099
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Momo application version 2.1.9
Description
The issue allows a non-root user to access confidential information, including usernames, passwords, and access tokens, which are stored insecurely in cleartext on the system. This can be achieved by accessing Logcat.
Recommendations
For Momo application version 2.1.9, consider restricting access to Logcat to minimize the risk of exploitation until a secure method of storing sensitive information is implemented.
Exploit
Fix
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Momo