PT-2025-9706 · Maharashtra State Electricity Distribution Company Limited · Maharashtra State Electricity Distribution Company Limited Mahavitran Ios Application

Tejas Nitin Pingulkar

·

Published

2025-03-04

·

Updated

2025-03-21

·

CVE-2021-41719

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Maharashtra State Electricity Distribution Company Limited Mahavitran IOS Application version 16.1
Description The issue concerns the Maharashtra State Electricity Distribution Company Limited Mahavitran IOS Application, which uses the GET method to process requests containing sensitive information, such as user account name and password. This can lead to exposure of the sensitive information through the browser's history, referrers, web logs, and other sources.
Recommendations For version 16.1, consider modifying the application to use a more secure method, such as the POST method, to process requests containing sensitive information, and ensure that sensitive data like user account name and password are properly encrypted and protected. As a temporary workaround, restrict access to the application's history and referrers to minimize the risk of sensitive information exposure.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41719

Affected Products

Maharashtra State Electricity Distribution Company Limited Mahavitran Ios Application