CVE-2025-65827
The mobile application is configured to allow clear text traffic to all domains and communicates with an API server over
The mobile application is configured to allow clear text traffic to all domains and communicates with an API server over HTTP. As a result, an adversary located "upstream" can intercept the traffic, inspect its contents, and modify the requests in transit. TThis may result in a total compromise of the user's account if the attacker intercepts a request with active authentication tokens or cracks the MD5 hash sent on login.
CRITICAL · CVSS 9.1
EPSS 0.00037
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0