Loading HuntDB...

Privacy policy contains hardcoded link using unencrypted HTTP

Low
U
Uber
Submitted None

Team Summary

Official summary from Uber

The link to Uber’s privacy policy was using the unencrypted `http://` scheme, making it possible for an attacker with the ability to Man-in-The-Middle (MiTM) traffic. This would allow them to replace normal responses with malicious content such as a phishing page. The content would then render within the Uber application, making for a credible phishing attack.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Code Injection