CVE-2018-11242 Information

Description

An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypted and have cleartext that might lead to sensitive information disclosure as demonstrated by data/com.makemytrip/databases and data/com.makemytrip/Cache SQLite database files.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Reference

https://gist.github.com/NinjaXshell/ba0aeee4b77b4bdea76d0c0c095d53b1 https://www.exploit-db.com/exploits/44690/

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

NONE

Base Severity

6.5

Share on: