peter bassill · operator
$ cve CVE-2018-11242 JSON

CVE-2018-11242 EXPLOIT

6.5
MEDIUM · CVSS 3.0 · EPSS 3.9% (pctl 90)

Patch early

A public exploit exists.

Description

An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypted and have cleartext that might lead to sensitive information disclosure, as demonstrated by data/com.makemytrip/databases and data/com.makemytrip/Cache SQLite database files.

Scoring

CVSS6.5 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS3.94% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-312
On CISA KEVno
Public exploityes
Published2018-05-20
Last modified2026-06-17

Affected (1)

VendorProduct
makemytripmakemytrip

Public exploits

SourceTitleDate
exploit-dbMakeMyTrip 7.2.4 - Information Disclosure2018-05-22

References

→ the Explorer  ·  watch your stack  ·  NVD