PT-2025-26759 · Ataturk University · Ata-Aof Mobile Application

Published

2025-06-24

·

Updated

2025-06-24

·

CVE-2025-4378

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions: Ataturk University ATA-AOF Mobile Application versions prior to 20.06.2025
Description: The issue affects the Ataturk University ATA-AOF Mobile Application, allowing for authentication abuse and bypass due to cleartext transmission of sensitive information and the use of hard-coded credentials.
Recommendations: For versions prior to 20.06.2025, update to a version released after 20.06.2025 to resolve the issue. As a temporary workaround, consider restricting access to sensitive features within the application until a patch is available.

Fix

Using Hardcoded Credentials

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2025-4378

Affected Products

Ata-Aof Mobile Application