CVE-2023-22362
HIGHSUSHIRO App for Android <4.0.31-<2.0.1 - Info Disclosure
Title source: llmDescription
SUSHIRO App for Android outputs sensitive information to the log file, which may result in an attacker obtaining a credential information from the log file. Affected products/versions are as follows: SUSHIRO Ver.4.0.31, Thailand SUSHIRO Ver.1.0.0, Hong Kong SUSHIRO Ver.3.0.2, Singapore SUSHIRO Ver.2.0.0, and Taiwan SUSHIRO Ver.2.0.1
References (6)
Core 6
Core References
Third Party Advisory
https://jvn.jp/en/jp/JVN84642320/
Scores
CVSS v3
7.5
EPSS
0.0045
EPSS Percentile
63.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-532
Status
published
Products (5)
akindo-sushiro/hong_kong_sushiro
3.0.3
akindo-sushiro/singapore_sushiro
2.0.3
akindo-sushiro/sushiro
4.0.31
akindo-sushiro/taiwan_sushiro
2.0.3
akindo-sushiro/thailand_sushiro
2.0.3
Published
Feb 13, 2023
Tracked Since
Feb 18, 2026