PT-2025-35777 · Unknown · Corona Virus Tracker App India
Aninda
+1
·
Published
2025-09-03
·
Updated
2025-09-08
·
CVE-2025-56608
CVSS v3.1
4.2
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Corona Virus Tracker App India version 1.0
Description
The Android application uses MD5 for digest authentication. The
handleDigest() function utilizes MessageDigest.getInstance("MD5") to hash credentials. MD5 is a cryptographic algorithm susceptible to hash collisions, potentially enabling replay, spoofing, or brute-force attacks, which could lead to unauthorized access.Recommendations
version 1.0: Replace MD5 with a stronger cryptographic hash function for authentication. Consider using SHA-256 or a similar modern algorithm.
Exploit
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Corona Virus Tracker App India