PT-2026-49146 · Moovit · Moovit Bus & Public Transit App
CVSS v3.1
5.3
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Moovit Bus & Public Transit App version 1.18
Description
A flaw in the
com.tranzmate component of the Android application allows for improper authorization within the handler for custom URL schemes. This issue requires local execution to manipulate the handler and bypass authorization controls.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Moovit Bus & Public Transit App