Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
EquityPandit 1.0 Insecure Logging Information Disclosure
Vulnerability Description
EquityPandit 1.0 contains an insecure logging vulnerability that allows attackers to capture sensitive user credentials by accessing developer console logs via Android Debug Bridge. Attackers can use adb logcat to extract plaintext passwords logged during the forgot password function, exposing user account credentials.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
通过私有数据的索引导致的信息暴露
Vulnerability Title
EquityPandit 安全漏洞
Vulnerability Description
EquityPandit是EquityPandit公司的一个提供股市分析、投资建议和市场预测的信息服务平台。 EquityPandit 1.0版本存在安全漏洞,该漏洞源于日志记录不安全,可能导致攻击者通过Android Debug Bridge访问开发者控制台日志,捕获敏感用户凭据。
CVSS Information
N/A
Vulnerability Type
N/A