Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hpx6-2j8w-26mq

Опубликовано: 10 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

The mobile application is configured to allow clear text traffic to all domains and communicates with an API server over HTTP. As a result, an adversary located "upstream" can intercept the traffic, inspect its contents, and modify the requests in transit. TThis may result in a total compromise of the user's account if the attacker intercepts a request with active authentication tokens or cracks the MD5 hash sent on login.

The mobile application is configured to allow clear text traffic to all domains and communicates with an API server over HTTP. As a result, an adversary located "upstream" can intercept the traffic, inspect its contents, and modify the requests in transit. TThis may result in a total compromise of the user's account if the attacker intercepts a request with active authentication tokens or cracks the MD5 hash sent on login.

EPSS

Процентиль: 10%
0.00036
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 9.1
nvd
около 2 месяцев назад

The mobile application is configured to allow clear text traffic to all domains and communicates with an API server over HTTP. As a result, an adversary located "upstream" can intercept the traffic, inspect its contents, and modify the requests in transit. TThis may result in a total compromise of the user's account if the attacker intercepts a request with active authentication tokens or cracks the MD5 hash sent on login.

EPSS

Процентиль: 10%
0.00036
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-319