← back
CVE-2016-6546CWE-313

iTrack Easy mobile application stores the user password in base-64 encoding/cleartext

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 0.4%
exploitation probability
0.4%top 66% of all CVEs
observed exploitation
nono source reports it
The iTrack Easy mobile application stores the account password used to authenticate to the cloud API in base64-encoding in the cache.db file. The base64 encoding format is considered equivalent to cleartext.
Affected products
iTrack · Easy