The VeryFitPro (com.veryfit2hr.second) application 3.2.8 for Android does all communication with the backend API over cleartext HTTP. This includes logins, registrations, and password change requests. This allows information theft and account takeover via network sniffing.
CVSS
No CVSS.
References
Configurations
No configuration.
Information
Published : 2021-06-16 12:15
Updated : 2021-06-18 18:15
NVD link : CVE-2021-32612
Mitre link : CVE-2021-32612
JSON object : View
Products Affected
No product.
CWE
No CWE.
