EquityPandit 1.0 contains an insecure logging vulnerability that allows attackers to capture sensitive user credentials by accessing developer console logs via Android Debug Bridge. Attackers can use adb logcat to extract plaintext passwords logged during the forgot password function, exposing user account credentials.
Metrics
Affected Vendors & Products
References
History
Sun, 22 Mar 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | EquityPandit 1.0 contains an insecure logging vulnerability that allows attackers to capture sensitive user credentials by accessing developer console logs via Android Debug Bridge. Attackers can use adb logcat to extract plaintext passwords logged during the forgot password function, exposing user account credentials. | |
| Title | EquityPandit 1.0 Insecure Logging Information Disclosure | |
| Weaknesses | CWE-612 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-22T13:38:40.499Z
Reserved: 2026-03-22T13:06:51.975Z
Link: CVE-2019-25605
No data.
Status : Received
Published: 2026-03-22T14:16:28.260
Modified: 2026-03-22T14:16:28.260
Link: CVE-2019-25605
No data.
OpenCVE Enrichment
No data.