Phonepe

Phonepe

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.02%
  • Veröffentlicht 25.05.2025 18:31:04
  • Zuletzt bearbeitet 03.06.2025 13:53:41

A vulnerability, which was classified as problematic, was found in PhonePe App 25.03.21.0 on Android. Affected is an unknown function of the file /data/data/com.phonepe.app/databases/ of the component SQLite Database. The manipulation leads to cleart...

  • EPSS 64.29%
  • Veröffentlicht 13.11.2023 03:15:07
  • Zuletzt bearbeitet 21.11.2024 07:29:48

Server-Side Request Forgery (SSRF) vulnerability in PhonePe PhonePe Payment Solutions.This issue affects PhonePe Payment Solutions: from n/a through 1.0.15.

  • EPSS 0.06%
  • Veröffentlicht 23.09.2018 22:29:00
  • Zuletzt bearbeitet 21.11.2024 03:54:20

The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to perform Account Takeover attacks by intercepting the user name and PIN during the initial configuration of the application. NOTE: the vend...

  • EPSS 0.32%
  • Veröffentlicht 23.09.2018 22:29:00
  • Zuletzt bearbeitet 21.11.2024 03:54:20

The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to perform Account Takeover attacks by exploiting its Forgot Password feature. NOTE: the vendor says that, to exploit this, the user has to e...

  • EPSS 0.33%
  • Veröffentlicht 23.09.2018 22:29:00
  • Zuletzt bearbeitet 21.11.2024 03:54:20

The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to discover the Credit/Debit card number, expiration date, and CVV number. NOTE: the vendor says that, to exploit this, the user has to expli...

  • EPSS 0.37%
  • Veröffentlicht 23.09.2018 22:29:00
  • Zuletzt bearbeitet 21.11.2024 03:54:20

The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to impersonate a user and set up their account without their knowledge. NOTE: the vendor says that, to exploit this, the user has to explicit...