mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-27 22:52:34 +02:00
20 lines
867 B
Markdown
20 lines
867 B
Markdown
### [CVE-2021-32612](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32612)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
The VeryFitPro (com.veryfit2hr.second) application 3.2.8 for Android does all communication with the backend API over cleartext HTTP. This includes logins, registrations, and password change requests. This allows information theft and account takeover via network sniffing.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- http://seclists.org/fulldisclosure/2021/Jun/45
|
|
- https://trovent.github.io/security-advisories/TRSA-2105-01/TRSA-2105-01.txt
|
|
- https://trovent.io/security-advisory-2105-01
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|