In GolfBuddy Course Manager 1.1, passwords are sent (with base64 encoding) via a GET request.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://help.golfbuddyglobal.com/sList.asp?searchproduct=29&searchcategory=5 | vendor advisory |
https://github.com/0xEmma/CVEs/blob/master/CVEs/CVE-2020-9337-Golf-Buddy-Insecure-Passwords.md | third party advisory |