Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jwm8-xr75-vc54

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Missing SSL Certificate Validation in the Nutfind.com application through 3.9.12 for Android allows a man-in-the-middle attacker to sniff and manipulate all API requests, including login credentials and location data.

Missing SSL Certificate Validation in the Nutfind.com application through 3.9.12 for Android allows a man-in-the-middle attacker to sniff and manipulate all API requests, including login credentials and location data.

EPSS

Процентиль: 37%
0.00159
Низкий

Связанные уязвимости

CVSS3: 5.9
nvd
больше 5 лет назад

Missing SSL Certificate Validation in the Nutfind.com application through 3.9.12 for Android allows a man-in-the-middle attacker to sniff and manipulate all API requests, including login credentials and location data.

EPSS

Процентиль: 37%
0.00159
Низкий