Vulnerabilities > Ohmibod

DATE CVE VULNERABILITY TITLE RISK
2017-12-01 CVE-2017-14487 Authentication Bypass by Spoofing vulnerability in Ohmibod Remote
The OhMiBod Remote app for Android and iOS allows remote attackers to impersonate users by sniffing network traffic for search responses from the OhMiBod API server and then editing the username, user_id, and token fields in data/data/com.ohmibod.remote2/shared_prefs/OMB.xml.
network
low complexity
ohmibod CWE-290
critical
9.1