Karnataka State Road Transport Corporation KSRTC AWATAR App Access Control Vulnerability

Vulnerability

A vulnerability in the KSRTC AWATAR app for Android, specifically in versions 1.4.3 and 1.4.2, has been identified. This vulnerability arises from incorrect access control, allowing sensitive user information such as email addresses, passwords, mobile numbers, and account IDs to be stored in plaintext within shared preferences. This insecure data storage practice exposes personal information to potential exploitation, violating mobile security best practices and OWASP Mobile Top 10 guidelines.

Impact

The vulnerability allows for the extraction of plaintext credentials and sensitive data from the app's shared preferences, which could lead to unauthorized access to user accounts, identity theft, and misuse of personal information.

Reproduction

To reproduce this vulnerability, install the KSRTC Karnataka app version 1.4.3 or 1.4.2 from the Google Play Store. After logging in with valid credentials, access the app's shared preferences directory to find sensitive information stored in plaintext.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.