ZeroHour

Vulnerabilities

3 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2016-6548
+2 in the same advisory: …6547 …6549
The Zizai Tech Nut mobile app makes requests via HTTP instead of HTTPS.

The Zizai Tech Nut mobile app makes requests via HTTP instead of HTTPS. These requests contain the user's authenticated session token with the URL. An attacker can capture these requests and reuse the session token to gain full access the user's account.

NVD description · AI analysis pending
9.8
group max
4% PoC
  • nutspace nut mobile