CVE Published: 13/03/2024 |
CVE Updated: 05/08/2024 |
CVE Year: 2024 Source: jpcert |
Vendor: Toyoko Inn IT Solution Co., Ltd. |
Product: Toyoko Inn official App for iOS Status : PUBLISHED
CVE-2024-27440 Description
The Toyoko Inn official App for iOS versions prior to 1.13.0 and Toyoko Inn official App for Android versions prior 1.3.14 don\'t properly verify server certificates, which allows a man-in-the-middle attacker to spoof servers and obtain sensitive information via a crafted certificate.