VYPR
Medium severity5.9NVD Advisory· Published Feb 13, 2020· Updated Jun 17, 2026

CVE-2020-8988

CVE-2020-8988

Description

The Voatz application 2020-01-01 for Android allows only 100 million different PINs, which makes it easier for attackers (after using root access to make a copy of the local database) to discover login credentials and voting history via an offline brute-force approach.

Affected products

3
  • Voatz/Voatz2 versions
    cpe:2.3:a:voatz:voatz:2020-01-01:*:*:*:*:android:*:*+ 1 more
    • cpe:2.3:a:voatz:voatz:2020-01-01:*:*:*:*:android:*:*
    • (no CPE)range: 2020-01-01
  • Voatz/Voatzdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.