← Back

Mahadiscom

mahadiscom

4 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Mahavitaran
mahavitaran

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mahadiscom
1Mahavitaran
Jun 17, 2026
Dec 8, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows remote attackers to control a users account.
1Mahadiscom
1Mahavitaran
Jul 9, 2026
Dec 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function
1Mahadiscom
1Mahavitaran
Jul 9, 2026
Dec 7, 2021
N/A· v4
4.2 MEDIUM· v3
1.9 LOW· v2
An issue was discovered in Mahavitaran android application 7.50 and below, allows local attackers to read cleartext username and password while the user is logged into the application.
1Mahadiscom
1Mahavitaran
Jun 17, 2026
Dec 2, 2021
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Mahavitaran android application 7.50 and prior transmit sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header, M...Show more
Mahavitaran android application 7.50 and prior transmit sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header, MITM or browser history.Show less