The Kickbase GmbH Kickbase Bundesliga Manager app before 2.2.1 – aka kickbase-bundesliga-manager/id678241305 – for iOS is vulnerable to a credentials leak due to transmitting a username and password in cleartext from client to server during registration and authentication.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bundesliga_manager | Kickbase | * | 2.2.1 (excluding) |