PoC Index

CVE-2018-11242

MEDIUM 6.5EPSS 4.1%

An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypted and have cleartext that might lead to sensitive information disclosure, as demonstrated by data/com.makemytrip/databases and data/com.makemytrip/Cache SQLite database files.

CVSS v3.0
6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v2.0
4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
EPSS
4.08% chance of exploitation in the next 30 days, 90th percentile
Published
2018-05-20
Updated
2024-08-05

ExploitDB entries (1)

References

Related