The server API in the Anda app relies on hardcoded credentials.
References
Link | Resource |
---|---|
https://gustavosilva.me/blog/2018/10/23/How-I-hacked-Anda-the-public-transportation-app-of-Porto-CVE-2018-13342.html | Third Party Advisory |
Configurations
Information
Published : 2018-10-24 15:29
Updated : 2019-01-09 13:53
NVD link : CVE-2018-13342
Mitre link : CVE-2018-13342
JSON object : View
CWE
CWE-798
Use of Hard-coded Credentials
Products Affected
linhandante
- anda