MiniTool Power Data Recovery version 11.6 and before contains an insecure in-app payment system that allows attackers to steal highly sensitive information through a man in the middle attack.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://0dr3f.github.io/cve/ | third party advisory |