The server API in the Anda app relies on hardcoded credentials.
References
Link | Resource |
---|---|
https://gustavosilva.me/blog/2018/10/23/How-I-hacked-Anda-the-public-transportation-app-of-Porto-CVE-2018-13342.html | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2018-10-24 22:29
Updated : 2024-02-28 16:48
NVD link : CVE-2018-13342
Mitre link : CVE-2018-13342
CVE.ORG link : CVE-2018-13342
JSON object : View
Products Affected
linhandante
- anda
CWE
CWE-798
Use of Hard-coded Credentials