CVE-2018-11242 EXPLOIT
6.5
MEDIUM · CVSS 3.0 · EPSS 3.9% (pctl 90)
Patch early
A public exploit exists.
Description
An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypted and have cleartext that might lead to sensitive information disclosure, as demonstrated by data/com.makemytrip/databases and data/com.makemytrip/Cache SQLite database files.
Scoring
| CVSS | 6.5 (MEDIUM, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 3.94% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-312 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-05-20 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| makemytrip | makemytrip |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | MakeMyTrip 7.2.4 - Information Disclosure | 2018-05-22 |
References
→ the Explorer · watch your stack · NVD