CVE-2018-11505
HIGHWerewolf Online 0.8.8 - Exposure of Firebase Token via Logcat Output
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-11505. PoCs published by ManhNho.
AI-analyzed exploit summary This exploit demonstrates an insecure logging vulnerability in Werewolf Online 0.8.8, where sensitive Firebase tokens are leaked via logcat. The PoC shows how an attacker can extract the token and use it in a PUT request to impersonate the user.
Description
The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat output.
Exploits (1)
This exploit demonstrates an insecure logging vulnerability in Werewolf Online 0.8.8, where sensitive Firebase tokens are leaked via logcat. The PoC shows how an attacker can extract the token and use it in a PUT request to impersonate the user.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N