Maharashtra State Electricity Distribution Company Limited Mahavitran iOS Application Sensitive Information Exposure Vulnerability

Vulnerability

A vulnerability exists in the Maharashtra State Electricity Distribution Company Limited (MSEB) iOS application, all versions through 16.1. The application improperly uses the GET method to transmit sensitive user information, including account names and passwords. This flaw can lead to exposure of credentials through various channels such as browser history, web server logs, referrer headers, and network interception.

Impact

Exploitation of this vulnerability allows for sensitive user credentials to be exposed in plaintext, creating a risk of unauthorized access to user accounts.

Reproduction

To reproduce this vulnerability, install Burp Suite to monitor network traffic. Then, open the MSEB iOS application and attempt to log in. Burp Suite will capture the GET request containing the password, revealing the login credentials in plaintext.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.3
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.