CVE-2021-33981 Information
Jun 07, 2022
cve
Description
An insecure direct object vulnerability in hunting/fishing license retrieval function of the \Fish | Hunt FL\ iOS app versions 3.8.0 and earlier allows a remote authenticated attacker to retrieve other people’s personal information and images of their hunting/fishing licenses.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Reference
https://gist.github.com/p4lsec/1f024d96b44ea733cdae0605c7ce8a49
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
4.3
Share on: