CVE-2020-8988

The Voatz application 2020-01-01 for Android allows only 100 million different PINs, which makes it easier for attackers (after using root access to make a copy of the local database) to discover login credentials and voting history via an offline brute-force approach.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:voatz:voatz:2020-01-01:*:*:*:*:android:*:*

Information

Published : 2020-02-13 13:15

Updated : 2021-07-21 04:39


NVD link : CVE-2020-8988

Mitre link : CVE-2020-8988


JSON object : View

CWE
CWE-330

Use of Insufficiently Random Values

CWE-521

Weak Password Requirements

Advertisement

dedicated server usa

Products Affected

voatz

  • voatz