An issue found in ALBIS Co. ALBIS v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp ALBIS function.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Link | Tags |
---|---|
http://albis.com | product |
https://github.com/syz913/CVE-reports/blob/main/CVE-2023-31821.md | third party advisory exploit |