CVE-2019-25605
Received
Received - Intake
Insecure Logging in EquityPandit 1.0 Exposes User Credentials
Publication date: 2026-03-22
Last updated on: 2026-03-22
Assigner: VulnCheck
Description
Description
EquityPandit 1.0 contains an insecure logging vulnerability that allows attackers to capture sensitive user credentials by accessing developer console logs via Android Debug Bridge. Attackers can use adb logcat to extract plaintext passwords logged during the forgot password function, exposing user account credentials.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| equitypandit | equitypandit | 1.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-612 | The product creates a search index of private or sensitive documents, but it does not properly limit index access to actors who are authorized to see the original information. |