The VeryFitPro (com.veryfit2hr.second) application 3.2.8 for Android does all communication with the backend API over cleartext HTTP. This includes logins, registrations, and password change requests. This allows information theft and account takeover via network sniffing.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-06-16T11:53:54

Updated: 2021-06-18T17:06:10

Reserved: 2021-05-12T00:00:00


Link: CVE-2021-32612

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-06-16T12:15:12.727

Modified: 2021-07-12T16:57:21.613


Link: CVE-2021-32612

JSON object: View

cve-icon Redhat Information

No data.

CWE