Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mhp8-7xp2-chw4

Опубликовано: 29 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.9
CVSS3: 5.1

Описание

"SwitchBot" App for iOS/Android contains an insertion of sensitive information into log file vulnerability in versions V6.24 through V9.12. If this vulnerability is exploited, sensitive user information may be exposed to an attacker who has access to the application logs.

"SwitchBot" App for iOS/Android contains an insertion of sensitive information into log file vulnerability in versions V6.24 through V9.12. If this vulnerability is exploited, sensitive user information may be exposed to an attacker who has access to the application logs.

EPSS

Процентиль: 2%
0.00013
Низкий

5.9 Medium

CVSS4

5.1 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 5.1
nvd
6 месяцев назад

"SwitchBot" App for iOS/Android contains an insertion of sensitive information into log file vulnerability in versions V6.24 through V9.12. If this vulnerability is exploited, sensitive user information may be exposed to an attacker who has access to the application logs.

EPSS

Процентиль: 2%
0.00013
Низкий

5.9 Medium

CVSS4

5.1 Medium

CVSS3

Дефекты

CWE-532