logo

Database

Description

Business insights from mobile app usage analytics are obtained via a Swagger URL exposed along with the APIKey.

Impact

Obtain business information about the analytics of the mobile application.

Recommendation

According to the classification of the found information, establish the necessary controls so that the information is accessible only to the indicated persons.

Threat

Unauthenticated external attacker in the application.

Expected Remediation Time

⏱️ 30 minutes.

Score

Default score using CVSS 4.0. It may change depending on the context of the src.

Base 4.0

Attack vector

N

Attack complexity

L

Attack requirements

N

Privileges required

N

User interaction

N

Confidentiality (VC)

L

Integrity (VI)

N

Availability (VA)

N

Confidentiality (SC)

N

Integrity (SI)

N

Availability (SA)

N

Threat 4.0

Exploit maturity

X

Vector string

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N