RSS   Vulnerabilities for 'Mahavitaran'   RSS

2021-12-08
 
CVE-2020-27416

CWE-613
 

 
Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows remote attackers to control a users account.

 
2021-12-07
 
CVE-2021-41716

CWE-287
 

 
Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function

 
 
CVE-2020-27413

CWE-522
 

 
An issue was discovered in Mahavitaran android application 7.50 and below, allows local attackers to read cleartext username and password while the user is logged into the application.

 
2021-12-02
 
CVE-2020-27414

CWE-200
 

 
Mahavitaran android application 7.50 and prior transmit sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header, MITM or browser history.

 


Copyright 2024, cxsecurity.com

 

Back to Top