We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-38480



Assignerjpcert
Reserved2024-06-18
Published2024-07-01
Updated2024-08-02

Description

"Piccoma" App for Android and iOS versions prior to 6.20.0 uses a hard-coded API key for an external service, which may allow a local attacker to obtain the API key. Note that the users of the app are not directly affected by this vulnerability.

Problem types

Use of Hard-coded Credentials

Product status

prior to 6.20.0
affected

prior to 6.20.0
affected

References

https://play.google.com/store/apps/details?id=jp.kakao.piccoma

https://apps.apple.com/jp/app/%E3%83%94%E3%83%83%E3%82%B3%E3%83%9E/id1091496983

https://jvn.jp/en/jp/JVN01073312/

cve.org CVE-2024-38480

nvd.nist.gov CVE-2024-38480

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.