CVE-2019-25605
EquityPandit 1.0 contains an insecure logging vulnerability that allows attackers to capture sensitive user credentials by accessing developer console logs via Android Debug Bridge. Attackers can use adb logcat to extract plaintext passwords logged during the forgot password function, exposing user account credentials.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.27%
- CWE
- CWE-612
- Published
- 2026-03-22
- Last modified
- 2026-03-23
Affected products
- Play EquityPandit
Weakness type
Related vulnerabilities
- CVE-2025-3660 — Petlibro Smart Pet Feeder Platform through 1.7.31 Broken Access Control via API endpoint
- CVE-2025-3654 — Petlibro Smart Pet Feeder Platform through 1.7.31 Information Disclosure via API endpoint
- CVE-2025-3653 — Petlibro Smart Pet Feeder through 1.7.31 Platform Improper Access Control via API endpoint
- CVE-2025-57756 — Contao discloses sensitive information in the front end search index
- CVE-2024-49071 — Windows Defender Information Disclosure Vulnerability
- CVE-2024-25635 — IDOR Vulnerability: Allowing Organization Owner to view the other Organizations API KEY and USERS
- CVE-2023-4560 — Improper Authorization of Index Containing Sensitive Information in omeka/omeka-s
- CVE-2022-41918 — Issue with fine-grained access control of indices backing data streams