EquityPandit 1.0 contains an insecure logging vulnerability that allows attackers to capture sensitive user credentials by accessing developer console logs via Android Debug Bridge. Attackers can use adb logcat to extract plaintext passwords logged during the forgot password function, exposing user account credentials.
Subscriptions
No data.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 22 Mar 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | EquityPandit 1.0 contains an insecure logging vulnerability that allows attackers to capture sensitive user credentials by accessing developer console logs via Android Debug Bridge. Attackers can use adb logcat to extract plaintext passwords logged during the forgot password function, exposing user account credentials. | |
| Title | EquityPandit 1.0 Insecure Logging Information Disclosure | |
| Weaknesses | CWE-612 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-22T13:38:40.499Z
Reserved: 2026-03-22T13:06:51.975Z
Link: CVE-2019-25605
No data.
Status : Received
Published: 2026-03-22T14:16:28.260
Modified: 2026-03-22T14:16:28.260
Link: CVE-2019-25605
No data.
OpenCVE Enrichment
No data.
Weaknesses