Mobile App Wall Of Shame - Trip38
ID: 96974dcc-0ae7-5d6e-af84-39aba14122ca
STIX ID: report--96974dcc-0ae7-5d6e-af84-39aba14122ca
Feed Name: Zscaler Security Research Blog
**Executive Summary:** Zscaler ThreatLabZ discovered that the Trip38 Travel Assistant mobile app (iOS and Android) transmits sensitive user data — including name, email, password, location and trip details — over unencrypted plain-text API calls, exposing users to MITM attacks and credential/privacy theft; the vulnerability is mapped to OWASP Mobile Top 10 M3 (Insecure Communication) and M4 (Insecure Authentication), and the developer plus platform vendors have been notified.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
