An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypted and have cleartext that might lead to sensitive information disclosure, as demonstrated by data/com.makemytrip/databases and data/com.makemytrip/Cache SQLite database files.
References
Link | Resource |
---|---|
https://gist.github.com/NinjaXshell/ba0aeee4b77b4bdea76d0c0c095d53b1 | Third Party Advisory |
https://www.exploit-db.com/exploits/44690/ | Exploit Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2018-05-20 14:29
Updated : 2024-02-04 19:46
NVD link : CVE-2018-11242
Mitre link : CVE-2018-11242
CVE.ORG link : CVE-2018-11242
JSON object : View
Products Affected
makemytrip
- makemytrip
CWE
CWE-312
Cleartext Storage of Sensitive Information