PT-2025-26759 · Ataturk University · Ata-Aof Mobile Application
Published
2025-06-24
·
Updated
2025-06-24
·
CVE-2025-4378
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions:
Ataturk University ATA-AOF Mobile Application versions prior to 20.06.2025
Description:
The issue affects the Ataturk University ATA-AOF Mobile Application, allowing for authentication abuse and bypass due to cleartext transmission of sensitive information and the use of hard-coded credentials.
Recommendations:
For versions prior to 20.06.2025, update to a version released after 20.06.2025 to resolve the issue. As a temporary workaround, consider restricting access to sensitive features within the application until a patch is available.
Fix
Using Hardcoded Credentials
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ata-Aof Mobile Application