PT-2021-5217 · Unknown · Mahavitaran
Published
2021-12-07
·
Updated
2021-12-09
·
CVE-2020-27413
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mahavitaran android application versions 7.50 and below
Description
The issue is related to insufficient protection of registration data in the Mahavitaran android application. This allows local attackers to read cleartext
username and password while the user is logged into the application.Recommendations
For Mahavitaran android application versions 7.50 and below, consider updating to a version above 7.50 to resolve the issue. As a temporary workaround, restrict access to sensitive information within the application to minimize the risk of exploitation. Avoid using the application with sensitive data until the issue is resolved.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mahavitaran