The Sleipnir Mobile application 2.12.1 and earlier and Sleipnir Mobile Black Edition application 2.12.1 and earlier for Android provide Geolocation API data without verifying user consent, which allows remote attackers to obtain sensitive location information via a web site that makes API calls.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2014-01-22 13:55
Updated : 2014-08-11 08:04
NVD link : CVE-2014-0806
Mitre link : CVE-2014-0806
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
fenrir-inc
- sleipnir_mobile