What the vulnerability does
01Description
Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.
Explanation of Vulnerability in Simple Terms
iCARRY version 2.9 and earlier leaks sensitive information in outbound network traffic. An attacker on the network path can intercept unencrypted data transmissions to read exposed details. No authentication or user interaction is required. Update to a version newer than 2.9 when available.
What an attacker can do
Read sensitive information from network traffic sent by the application.
Potential impact on your site
Sensitive data may be exposed to anyone monitoring network traffic if iCARRY communicates over unencrypted channels.
Conditions required to exploit
Network access to intercept traffic between the application and remote servers.
Key dates
External resources
Related vulnerabilities