An issue was discovered in the MensaMax (aka com.breustedt.mensamax) application 4.3 for Android. Cleartext Transmission of Sensitive Information allows man-in-the-middle attackers to eavesdrop authentication information between the application and the server.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Link | Tags |
---|---|
https://advisories.e2security.de/2018/E2SA-2018-01.txt | third party advisory exploit |
https://seclists.org/bugtraq/2018/Oct/3 | mailing list exploit third party advisory |