Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2024-54681

Disclosure Date: January 17, 2025 (last updated January 18, 2025)
Multiple bash files were present in the application's private directory. Bash files can be used on their own, by an attacker that has already full access to the mobile platform to compromise the translations for the application.
0
Attacker Value
Unknown

CVE-2024-53683

Disclosure Date: January 17, 2025 (last updated January 18, 2025)
A valid set of credentials in a .js file and a static token for communication were obtained from the decompiled IPA. An attacker could use the information to disrupt normal use of the application by changing the translation files and thus weaken the integrity of normal use.
0
Attacker Value
Unknown

CVE-2024-45832

Disclosure Date: January 17, 2025 (last updated January 18, 2025)
Hard-coded credentials were included as part of the application binary. These credentials served as part of the application authentication flow and communication with the mobile application. An attacker could access unauthorized information.
0
Attacker Value
Unknown

CVE-2016-10979

Disclosure Date: September 17, 2019 (last updated November 27, 2024)
The fossura-tag-miner plugin before 1.1.5 for WordPress has XSS.
Attacker Value
Unknown

CVE-2016-10978

Disclosure Date: September 17, 2019 (last updated November 27, 2024)
The fossura-tag-miner plugin before 1.1.5 for WordPress has CSRF.