该漏洞存在于 Schmooze 应用中,原因是客户端应用程序中使用了硬编码的凭据和密码学密钥。未认证的远程攻击者可以通过反编译分发的应用程序包,提取其中嵌入的凭据和密码学密钥来利用此漏洞。 成功利用此漏洞可能使攻击者能够未经授权访问后端和云资源,并在目标系统上伪造客户端请求。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Schmooze | Schmooze dating mobile Application | Android versions 5.2.7 (build 452) and prior | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet