Missing SSL Certificate Validation in the Nutfind.com application through 3.9.12 for Android allows a man-in-the-middle attacker to sniff and manipulate all API requests, including login credentials and location data.
References
Link Resource
https://arxiv.org/pdf/2005.08208.pdf Technical Description Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-06-12T22:15:51

Updated: 2020-06-12T22:15:51

Reserved: 2019-09-11T00:00:00


Link: CVE-2019-16252

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-06-12T23:15:10.040

Modified: 2020-06-22T15:46:51.937


Link: CVE-2019-16252

JSON object: View

cve-icon Redhat Information

No data.

CWE