An issue found in Inageya v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp Inageya function.
The product does not encrypt sensitive or critical information before storage or transmission.
Link | Tags |
---|---|
http://inageya.com | product |
https://github.com/syz913/CVE-reports/blob/main/CVE-2023-31825.md | third party advisory exploit |