vendor:
miSecureMessages
by:
Jatin Kataria
8,8
CVSS
HIGH
Session Management Vulnerability
287
CWE
Product Name: miSecureMessages
Affected Version From: Client=4.0.1, Server=6.2.4552.30017
Affected Version To: Client=4.0.1, Server=6.2.4552.30017
Patch Exists: No
Related CWE: N/A
CPE: o:amtelco:misecuremessages
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: iOS, Android
2018
Session Management Vulnerability
miSecureMessages lacks any sort of session management. Among other things, this allows any user to modify the xml requests to retrieve other users messages. The contactID parameter can be modified to retrieve messages from other users.
Mitigation:
The vendor should implement proper session management to prevent unauthorized access to user messages.