Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function
References
Link | Resource |
---|---|
https://cvewalkthrough.com/cve-2021-41716-mahavitaran-android-application-account-take-over-via-otp-fixation/ | Exploit Third Party Advisory |
http://maharashtra.com | Not Applicable |
Configurations
Information
Published : 2021-12-07 11:15
Updated : 2021-12-08 06:48
NVD link : CVE-2021-41716
Mitre link : CVE-2021-41716
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
mahadiscom
- mahavitaran