Vulnerabilities > Myfwc > Fish Hunt FL > 2.0

DATE CVE VULNERABILITY TITLE RISK
2021-09-08 CVE-2021-33981 Authorization Bypass Through User-Controlled Key vulnerability in Myfwc Fish | Hunt FL
An insecure, direct object vulnerability in hunting/fishing license retrieval function of the "Fish | Hunt FL" iOS app versions 3.8.0 and earlier allows a remote authenticated attacker to retrieve other people's personal information and images of their hunting/fishing licenses.
network
low complexity
myfwc CWE-639
4.0
2021-09-08 CVE-2021-33982 Insufficient Session Expiration vulnerability in Myfwc Fish | Hunt FL
An insufficient session expiration vulnerability exists in the "Fish | Hunt FL" iOS app version 3.8.0 and earlier, which allows a remote attacker to reuse, spoof, or steal other user and admin sessions.
network
low complexity
myfwc CWE-613
5.0