The server API in the Anda app relies on hardcoded credentials.
References
Configurations
History
21 Nov 2024, 03:46
Type | Values Removed | Values Added |
---|---|---|
References | () https://gustavosilva.me/blog/2018/10/23/How-I-hacked-Anda-the-public-transportation-app-of-Porto-CVE-2018-13342.html - Third Party Advisory |
Information
Published : 2018-10-24 22:29
Updated : 2024-11-21 03:46
NVD link : CVE-2018-13342
Mitre link : CVE-2018-13342
CVE.ORG link : CVE-2018-13342
JSON object : View
Products Affected
linhandante
- anda
CWE
CWE-798
Use of Hard-coded Credentials