CVE-2019-25605CWE-612

EquityPandit 1.0 Insecure Logging Information Disclosure

High · published March 22, 2026

CVSS v4.0
8.7
EPSS
0%
Percentile
19.4
In the wild
Unconfirmed
What it is

EquityPandit 1.0 contains an insecure logging vulnerability that allows attackers to capture sensitive user credentials by accessing developer console logs via Android Debug Bridge. Attackers can use adb logcat to extract plaintext passwords logged during the forgot password function, exposing user account credentials.

The record
Technical detail
CVSS v4.0
8.7 · HIGH
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS
0.00273 · 19.4th percentile
Weakness
CWE-612 · Improper Authorization of Index Containing Sensitive Information
Published
2026-03-22T13:38Z
EPSS history
Timeline
  • 22 MAR 13:38Z
    EquityPandit 1.0 Insecure Logging Information Disclosure
    cvelistv5