CVE-2019-17396

CRITICAL

PowerSchool Mobile < 1.1.8 - Sensitive Information Exposure via Logcat

Title source: llm
STIX 2.1

Description

In the PowerSchool Mobile application 1.1.8 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.

References (1)

Core 1
Core References
Patch, Third Party Advisory x_refsource_misc
https://pastebin.com/9VBiRpAR

Scores

CVSS v3 9.8
EPSS 0.0122
EPSS Percentile 64.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-532
Status published
Products (1)
powerschool/powerschool_mobile < 1.1.8
Published Oct 15, 2019
Tracked Since Feb 18, 2026