Home / os / winnt

Platinum Mobile 1.0.4.850 Authorization Bypass

Posted on 03 October 2020

Platinum Mobile version 1.0.4.850 has a broken access control. The mobile application connects to the company-specific server, which does not properly restrict the access to confidential data. Thus, an authenticated attacker can disclose the company's payroll, personal information of other employees without having appropriate privileges to do so.

 

TOP