CVE-2016-6546
13.07.2018, 20:29
The iTrack Easy mobile application stores the account password used to authenticate to the cloud API in base64-encoding in the cache.db file. The base64 encoding format is considered equivalent to cleartext.Enginsight
Vendor | Product | Version |
---|---|---|
kkmcn | itrackeasy | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-313 - Cleartext Storage in a File or on DiskThe application stores sensitive information in cleartext in a file, or on disk.
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
References