BLUVOYIX Password Exposure Vulnerability via Unauthenticated APIs
Vulnerability
A vulnerability in BLUVOYIX exists due to improper password storage and exposure through unauthenticated APIs. This allows remote attackers to send crafted HTTP requests to the users API, retrieving plaintext passwords of all users. Exploitation could lead to full access to customer data and complete compromise of the platform by logging in with an exposed admin email and password.
Impact
Successful exploitation allows access to all user plaintext passwords, leading to unauthorized access to customer data and potential full compromise of the platform using an admin account.
Added: Jan 14, 2026, 3:19 PM
Updated: Jan 14, 2026, 4:29 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
7.5exploitability
4.4remediation
0.0relevance
2.1threat
0.0urgency
10.0incentive
0.0Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
