Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7gf3-3v44-pwm2

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

An issue was discovered in the RENPHO application 3.0.0 for iOS. It transmits JSON data unencrypted to a server without an integrity check, if a user changes personal data in his profile tab (e.g., exposure of his birthday) or logs into his account (i.e., exposure of credentials).

An issue was discovered in the RENPHO application 3.0.0 for iOS. It transmits JSON data unencrypted to a server without an integrity check, if a user changes personal data in his profile tab (e.g., exposure of his birthday) or logs into his account (i.e., exposure of credentials).

EPSS

Процентиль: 40%
0.0018
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-319
CWE-924

Связанные уязвимости

CVSS3: 6.8
nvd
больше 6 лет назад

An issue was discovered in the RENPHO application 3.0.0 for iOS. It transmits JSON data unencrypted to a server without an integrity check, if a user changes personal data in his profile tab (e.g., exposure of his birthday) or logs into his account (i.e., exposure of credentials).

EPSS

Процентиль: 40%
0.0018
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-319
CWE-924