An issue found in Entetsu Store v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp Entetsu Store function.
The product does not encrypt sensitive or critical information before storage or transmission.
Link | Tags |
---|---|
http://entetsu.com | product |
https://github.com/syz913/CVE-reports/blob/main/CVE-2023-31822.md | third party advisory exploit |