2.1
CVSSv2

CVE-2014-0647

Published: 28/01/2014 Updated: 09/10/2018
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Starbucks 2.6.1 application for iOS stores sensitive information in plaintext in the Crashlytics log file (/Library/Caches/com.crashlytics.data/com.starbucks.mystarbucks/session.clslog), which allows malicious users to discover usernames, passwords, and e-mail addresses via an application that reads session.clslog.

Vulnerable Product Search on Vulmon Subscribe to Product

starbucks starbucks 2.6.1

Exploits

Starbucks mobile application version 261 stores user credentials in the clear ...