AdForest Classified Android App Improper Access Control Vulnerability in Authentication Mechanism
Vulnerability
A vulnerability allowing improper access control has been identified in the AdForest - Classified Android App, version 4.0.12, developed by Muhammad Jawad Arshad. The issue arises in the app's authentication process, where a Base64-encoded email address is used as the authorization credential. This mechanism can be exploited by attackers to gain unauthorized access to user accounts. Successful exploitation may lead to account compromise, privacy violations, and potential misuse of the platform.
Impact
Exploitation of this vulnerability could result in unauthorized access to user accounts, allowing attackers to compromise accounts, breach privacy, and misuse the platform.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
