MiniTool Power Data Recovery version 11.6 and before contains an insecure in-app payment system that allows attackers to steal highly sensitive information through a man in the middle attack.
References
Link | Resource |
---|---|
https://0dr3f.github.io/cve/ | Third Party Advisory |
https://0dr3f.github.io/cve/ | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-09-19 16:15
Updated : 2024-11-21 08:13
NVD link : CVE-2023-38353
Mitre link : CVE-2023-38353
CVE.ORG link : CVE-2023-38353
JSON object : View
Products Affected
minitool
- power_data_recovery
CWE
CWE-295
Improper Certificate Validation