Note:
To exploit this vulnerability, the device must be rooted/jailbroken.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-50589 | This vulnerability exists in the Tinxy mobile app due to storage of logged-in user information in plaintext on the device database. An attacker with physical access to the rooted device could exploit this vulnerability by accessing its database leading to unauthorized access of user information such as username, email address and mobile number. Note: To exploit this vulnerability, the device must be rooted/jailbroken. |
Solution
Upgrade Tinxy Andriod app to version 663000 and iOS app to version 6.7.0 https://play.google.com/store/apps/details?id=com.tinxy https://apps.apple.com/in/app/tinxy/id1387370719 https://play.google.com/store/apps/details
Workaround
No workaround given by the vendor.
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 15 Apr 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability exists in the Tinxy mobile app due to storage of logged-in user information in plaintext on the device database. An attacker with physical access to the rooted device could exploit this vulnerability by accessing its database leading to unauthorized access of user information such as username, email address and mobile number. | This vulnerability exists in the Tinxy mobile app due to storage of logged-in user information in plaintext on the device database. An attacker with physical access to the rooted device could exploit this vulnerability by accessing its database leading to unauthorized access of user information such as username, email address and mobile number. Note: To exploit this vulnerability, the device must be rooted/jailbroken. |
Thu, 05 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mogify Infotech
Mogify Infotech tinxy Mobile App |
|
| CPEs | cpe:2.3:a:mogify_infotech:tinxy_mobile_app:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mogify Infotech
Mogify Infotech tinxy Mobile App |
|
| Metrics |
ssvc
|
Thu, 05 Dec 2024 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability exists in the Tinxy mobile app due to storage of logged-in user information in plaintext on the device database. An attacker with physical access to the rooted device could exploit this vulnerability by accessing its database leading to unauthorized access of user information such as username, email address and mobile number. | |
| Title | Information Disclosure Vulnerability in Tinxy | |
| Weaknesses | CWE-312 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-In
Published:
Updated: 2025-04-15T09:16:24.183Z
Reserved: 2024-12-03T11:39:35.089Z
Link: CVE-2024-12094
Updated: 2024-12-05T17:08:34.788Z
Status : Awaiting Analysis
Published: 2024-12-05T13:15:05.923
Modified: 2025-04-15T10:15:13.780
Link: CVE-2024-12094
No data.
OpenCVE Enrichment
No data.
EUVD