An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android. The login credentials are written into a log file on the device. Hence, an attacker with access to the logs can read them.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
http://seclists.org/fulldisclosure/2017/Jul/90 | third party advisory mailing list |