CVE-2019-25605CWE-612
EquityPandit 1.0 Insecure Logging Information Disclosure
High · published March 22, 2026
What it is
EquityPandit 1.0 contains an insecure logging vulnerability that allows attackers to capture sensitive user credentials by accessing developer console logs via Android Debug Bridge. Attackers can use adb logcat to extract plaintext passwords logged during the forgot password function, exposing user account credentials.
The record
Technical detail
- CVSS v4.0
- 8.7 · HIGH
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS
- 0.00273 · 19.4th percentile
- Weakness
- CWE-612 · Improper Authorization of Index Containing Sensitive Information
- Published
- 2026-03-22T13:38Z
EPSS history
Timeline