Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vxjg-xmrq-x393

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

In the "NQ Contacts Backup & Restore" application 1.1 for Android, no HTTPS is used for transmitting login and synced user data. When logging in, the username is transmitted in cleartext along with an SHA-1 hash of the password. The attacker can either crack this hash or use it for further attacks where only the hash value is required.

In the "NQ Contacts Backup & Restore" application 1.1 for Android, no HTTPS is used for transmitting login and synced user data. When logging in, the username is transmitted in cleartext along with an SHA-1 hash of the password. The attacker can either crack this hash or use it for further attacks where only the hash value is required.

EPSS

Процентиль: 36%
0.00153
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 9.8
nvd
больше 8 лет назад

In the "NQ Contacts Backup & Restore" application 1.1 for Android, no HTTPS is used for transmitting login and synced user data. When logging in, the username is transmitted in cleartext along with an SHA-1 hash of the password. The attacker can either crack this hash or use it for further attacks where only the hash value is required.

EPSS

Процентиль: 36%
0.00153
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-319