CVE-2019-11384

CRITICAL

Zalora app 6.15.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Zalora application 6.15.1 for Android stores confidential information insecurely on the system (i.e. plain text), which allows a non-root user to find out the username/password of a valid user via /data/data/com.zalora.android/shared_prefs/login_data.xml.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://pastebin.com/c90h9WfB

Scores

CVSS v3 9.8
EPSS 0.0099
EPSS Percentile 58.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-312
Status published
Products (1)
zalora/zalora 6.15.1
Published Apr 22, 2019
Tracked Since Feb 18, 2026