The Contact Customer Support feature in the TigerText Free Private Texting app before 3.1.402 for iOS sends a log-file e-mail message with unencrypted credentials, which allows remote attackers to obtain sensitive information by sniffing the network or leveraging access to an e-mail endpoint.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www.kb.cert.org/vuls/id/704916 | third party advisory us government resource |