High severity7.8NVD Advisory· Published Apr 25, 2022· Updated Jul 9, 2026
CVE-2021-36460
CVE-2021-36460
Description
VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords. This allows an attacker in possession of a hash to takeover a user's account, rendering the benefits of storing hashed passwords in the database useless.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- VeryFitPro/VeryFitProdescription
- Range: =3.2.8
Patches
Vulnerability mechanics
References
1- www.i-doo.cnnvdNot Applicable
News mentions
0No linked articles in our index yet.