PT-2024-21898 · Toyoko Inn · Toyoko Inn Official App For Android+1

Ryo Nihonyanagi

·

Published

2024-03-13

·

Updated

2024-08-05

·

CVE-2024-27440

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Toyoko Inn official App for iOS versions prior to 1.13.0 Toyoko Inn official App for Android versions prior to 1.3.14
Description The issue arises from the improper verification of server certificates, allowing a man-in-the-middle attacker to spoof servers. This can lead to the attacker obtaining sensitive information via a crafted certificate.
Recommendations For Toyoko Inn official App for iOS versions prior to 1.13.0, update to version 1.13.0 or later to resolve the issue. For Toyoko Inn official App for Android versions prior to 1.3.14, update to version 1.3.14 or later to resolve the issue.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2024-27440

Affected Products

Toyoko Inn Official App For Android
Toyoko Inn Official App For Ios