AdForest - Classified Android App version 4.0.12 (package name scriptsbundle.adforest), developed by Muhammad Jawad Arshad, contains an improper access control vulnerability in its authentication mechanism. The app uses a Base64-encoded email address as the authorization credential, which can be manipulated by attackers to gain unauthorized access to user accounts. Successful exploitation could result in account compromise, privacy breaches, and misuse of the platform.
Metrics
Affected Vendors & Products
References
History
Fri, 31 Oct 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google android Scriptsbundle Scriptsbundle adforest |
|
| Vendors & Products |
Google
Google android Scriptsbundle Scriptsbundle adforest |
Thu, 30 Oct 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Thu, 30 Oct 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AdForest - Classified Android App version 4.0.12 (package name scriptsbundle.adforest), developed by Muhammad Jawad Arshad, contains an improper access control vulnerability in its authentication mechanism. The app uses a Base64-encoded email address as the authorization credential, which can be manipulated by attackers to gain unauthorized access to user accounts. Successful exploitation could result in account compromise, privacy breaches, and misuse of the platform. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-10-30T00:00:00.000Z
Updated: 2025-10-30T20:41:17.147Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-61116
Updated: 2025-10-30T20:41:12.294Z
Status : Received
Published: 2025-10-30T16:15:36.230
Modified: 2025-10-30T21:15:35.480
Link: CVE-2025-61116
No data.