insecure-transport

1 article
Sort: New Top Best
clear filter
0

DuoLingo's TinyCards Android app was vulnerable to content injection attacks due to loading initial web content over unencrypted HTTP instead of HTTPS, allowing MITM attackers to inject arbitrary JavaScript and achieve code execution within the WebView. The vulnerability was fixed in version 1.0 (version code 10) released November 20, 2017.

CVE-2017-16905 DuoLingo TinyCards Google Play Security Reward Program Nightwatch Cybersecurity Yakov Shafranovich
wwws.nightwatchcybersecurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details