EquityPandit 1.0 contains an insecure logging vulnerability that allows attackers to capture sensitive user credentials by accessing developer console logs via Android Debug Bridge. Attackers can use adb logcat to extract plaintext passwords logged during the forgot password function, exposing user account credentials.
Metrics
Affected Vendors & Products
References
History
Mon, 23 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Play
Play equitypandit |
|
| Vendors & Products |
Play
Play equitypandit |
Sun, 22 Mar 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | EquityPandit 1.0 contains an insecure logging vulnerability that allows attackers to capture sensitive user credentials by accessing developer console logs via Android Debug Bridge. Attackers can use adb logcat to extract plaintext passwords logged during the forgot password function, exposing user account credentials. | |
| Title | EquityPandit 1.0 Insecure Logging Information Disclosure | |
| Weaknesses | CWE-612 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-03-22T13:38:40.499Z
Updated: 2026-03-22T13:38:40.499Z
Reserved: 2026-03-22T13:06:51.975Z
Link: CVE-2019-25605
No data.
Status : Awaiting Analysis
Published: 2026-03-22T14:16:28.260
Modified: 2026-03-23T14:31:37.267
Link: CVE-2019-25605
No data.