Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-36460

Опубликовано: 25 апр. 2022
Источник: nvd
CVSS3: 7.8
CVSS2: 4.6
EPSS Низкий

Описание

VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords. This allows an attacker in possession of a hash to takeover a user's account, rendering the benefits of storing hashed passwords in the database useless.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:veryfitpro_project:veryfitpro:*:*:*:*:*:android:*:*
Версия до 3.3.7 (включая)
cpe:2.3:a:veryfitpro_project:veryfitpro:*:*:*:*:*:iphone_os:*:*
Версия до 3.3.7 (включая)

EPSS

Процентиль: 32%
0.00125
Низкий

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 7.8
github
почти 4 года назад

VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords. This allows an attacker in possession of a hash to takeover a user's account, rendering the benefits of storing hashed passwords in the database useless.

EPSS

Процентиль: 32%
0.00125
Низкий

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-287