CVE-2017-11706
Last modified
CVE-2017-11706 is a vulnerability of currently unknown severity. The Boozt Fashion application before 2.3.4 for Android allows remote attackers to read login credentials by sniffing the network and leveraging the lack of SSL. NOTE: the vendor response, before the application was changed to enable SSL logins, was "At the moment that is an accepted risk. EPSS estimates a 1.41% chance of exploitation in the next 30 days.
Description
The Boozt Fashion application before 2.3.4 for Android allows remote attackers to read login credentials by sniffing the network and leveraging the lack of SSL. NOTE: the vendor response, before the application was changed to enable SSL logins, was "At the moment that is an accepted risk. We only have https on the checkout part of the site."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Boozt | Boozt | <= 2.3.3 |
References
- https://hackerone.com/reports/166712Third Party Advisory
- https://hackerone.com/reports/166712Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-11706?
How severe is CVE-2017-11706?
How do I fix CVE-2017-11706?
Are you affected by CVE-2017-11706?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
