Cleartext Transmission and Hard-coded Credentials in ATA-AOF Mobile Application by Ataturk University
CVE-2025-4378

10CRITICAL

Key Information:

Vendor
CVE Published:
24 June 2025

What is CVE-2025-4378?

The ATA-AOF Mobile Application developed by Ataturk University has been found to have significant security vulnerabilities including the cleartext transmission of sensitive information and the use of hard-coded credentials. These issues can lead to authentication abuse and bypass, exposing users' data to potential interception by unauthorized entities. This vulnerability affects the application versions released before June 20, 2025, making it critical for users to update their applications and enhance their security posture to prevent exploitation.

Affected Version(s)

ATA-AOF Mobile Application 0 < 20.06.2025

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Enes Alperen HĂĽrĂĽm
Berat UÄźur Demirkan
.
CVE-2025-4378 : Cleartext Transmission and Hard-coded Credentials in ATA-AOF Mobile Application by Ataturk University