Vulnerability Description
The Momo application 2.1.9 for Android stores confidential information insecurely on the system (i.e., in cleartext), which allows a non-root user to find out the username/password of a valid user and a user's access token via Logcat.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Momo Project | Momo | 2.1.9 |
Related Weaknesses (CWE)
References
- https://pastebin.com/SgVPb7LbExploitThird Party Advisory
- https://pastebin.com/SgVPb7LbExploitThird Party Advisory
FAQ
What is CVE-2019-13099?
CVE-2019-13099 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The Momo application 2.1.9 for Android stores confidential information insecurely on the system (i.e., in cleartext), which allows a non-root user to find out the username/password of a valid user and...
How severe is CVE-2019-13099?
CVE-2019-13099 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-13099?
Check the references section above for vendor advisories and patch information. Affected products include: Momo Project Momo.