The Rediffmail (aka com.rediff.mail.and) application 2.2.6 for Android has cleartext mail content in file storage, persisting after a logout.
The product does not encrypt sensitive or critical information before storage or transmission.
Link | Tags |
---|---|
https://twitter.com/811Rishi/status/1122603147183017985 | third party advisory exploit |