PT-2025-9706 · Maharashtra State Electricity Distribution Company Limited · Maharashtra State Electricity Distribution Company Limited Mahavitran Ios Application
Tejas Nitin Pingulkar
·
Published
2025-03-04
·
Updated
2025-03-21
·
CVE-2021-41719
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Maharashtra State Electricity Distribution Company Limited Mahavitran IOS Application version 16.1
Description
The issue concerns the Maharashtra State Electricity Distribution Company Limited Mahavitran IOS Application, which uses the GET method to process requests containing sensitive information, such as
user account name and password. This can lead to exposure of the sensitive information through the browser's history, referrers, web logs, and other sources.Recommendations
For version 16.1, consider modifying the application to use a more secure method, such as the POST method, to process requests containing sensitive information, and ensure that sensitive data like
user account name and password are properly encrypted and protected. As a temporary workaround, restrict access to the application's history and referrers to minimize the risk of sensitive information exposure.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Maharashtra State Electricity Distribution Company Limited Mahavitran Ios Application