VendorsMahadiscommahavitaranany version
Vulnerabilities

Mahadiscom (Maharashtra State Electricity Distribution Company Limited) Mahavitaran any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2020-27416
Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows remote attackers to control a users account.
Published 2021-12-08 · Modified
9.8EPSS 0.016
CVE-2021-41716
Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function
Published 2021-12-07 · Modified
9.8EPSS 0.013
CVE-2020-27414
Mahavitaran android application 7.50 and prior transmit sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header, MITM or browser history.
Published 2021-12-02 · Modified
5.9EPSS 0.010
CVE-2020-27413
An issue was discovered in Mahavitaran android application 7.50 and below, allows local attackers to read cleartext username and password while the user is logged into the application.
Published 2021-12-07 · Modified
4.2EPSS 0.003