-
Type:
Epic
-
Resolution: Unresolved
-
Priority:
High
-
None
-
Affects Version/s: None
-
None
-
VAPT vulnerabilities
FLW (Sakhi 2.0/ Utprerona 2.0) Mobile App was under went Security Audit testing using Vulnerability Assessment & Penetration Testing (VAPT) by CODEC Networks.
Below are the reported vulnerabilities in Security Audit:
1. vulnerabilities related to Android App (FLW App) :
- Sensitive User Information available inside Unencrypted Shared Preferences
- Extraneous Functionality
- Improper Platform Usage - Debuggable: ClearText Traffic
- Sensitive Information Data
- Task Switching
- Copy Paste Buffer
- Lack of code obfuscation
- APP runs on Rooted Device
2. vulnerabilities related to backend (AMRIT) :
- Swagger API Disclosure
- Improper Session Management
- CORS
Note: Attached the vulnerability report