CVE-2017-14711

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
13/11/2017
Last modified:
20/04/2025

Description

The Kickbase GmbH "Kickbase Bundesliga Manager" app before 2.2.1 -- aka kickbase-bundesliga-manager/id678241305 -- for iOS is vulnerable to a credentials leak due to transmitting a username and password in cleartext from client to server during registration and authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kickbase:bundesliga_manager:*:*:*:*:*:iphone_os:*:* 2.2.1 (excluding)