HIGH
Union Pay up to 3.3.12, for iOS mobile apps, contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability, allows attackers to shop for free in merchants' websites and mobile apps, via a crafted authentication code (MAC) which is generated based on a secret key which is NULL
Published Apr 6, 2021
7.5
HIGHCVSS 3.1
EPSS 0.90%
Description
Affected products
Remediation
References (4)
Change history (0)
No recorded changes yet.