PT-2026-5872 · Mobywatel · Mobywatel
CVE-2025-11598
·
Publicado
2026-02-03
·
Atualizado
2026-02-03
CVSS v4.0
1.0
Baixa
| Vetor | AV:P/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
mObywatel versions prior to 4.71.0
Description
An unauthorized user can view an account owner's personal information in the minimized application window using the App Switcher, even after the login session has ended. Reopening the application requires the user to log in again. The data exposed depends on the last application view displayed before minimization.
Recommendations
Update to version 4.71.0 or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mobywatel