CVE Database
/

CVE-2024-32988

Back to search

CVE-2024-32988

Published: May 22, 2024

Modified: Aug 2, 2024

PUBLISHED

Description

'OfferBox' App for Android versions 2.0.0 to 2.3.17 and 'OfferBox' App for iOS versions 2.1.7 to 2.6.14 use a hard-coded secret key for JWT. Secret key for JWT may be retrieved if the application binary is reverse-engineered.

VendorProductVersions

i-plug inc.

'OfferBox' App for Android

affected
2.0.0 to 2.3.17

i-plug inc.

'OfferBox' App for iOS

affected
2.1.7 to 2.6.14

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now