logo

Mobile App Wall Of Shame: Shaadi.com

ID: f2d1ae7d-0d13-573d-b039-c51624553380

STIX ID: report--f2d1ae7d-0d13-573d-b039-c51624553380

Feed Name: Zscaler Security Research Blog

Threat Score
55/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

The report documents a serious security flaw in the Shaadi.com mobile applications (iOS and Android) where user credentials (username/password) and other registration data are sent in cleartext over HTTP during account registration and login. The finding is confirmed on specific app versions (iOS v4.2.1 and Android v4.2.2/4.1.3) and includes request/response captures showing POST/GET traffic containing plaintext credentials, which could allow attackers on the network to intercept credentials and compromise user accounts and personal data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.