Vulnerabilities > CVE-2013-0128 - Credentials Management vulnerability in Tigertext 3.1

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
tigertext
CWE-255

Summary

The Contact Customer Support feature in the TigerText Free Private Texting app before 3.1.402 for iOS sends a log-file e-mail message with unencrypted credentials, which allows remote attackers to obtain sensitive information by sniffing the network or leveraging access to an e-mail endpoint.

Vulnerable Configurations

Part Description Count
Application
Tigertext
1

Common Weakness Enumeration (CWE)