CVE-2024-43201 - Planet Fitness Workouts TLS Certificate Validation Vulnerability

3 weeks ago 9
ARTICLE AD BOX
CVE ID : CVE-2024-43201
Published : Sept. 23, 2024, 8:15 p.m. | 24 minutes ago
Description : The Planet Fitness Workouts iOS and Android mobile apps prior to version 9.8.12 (released on 2024-07-25) fail to properly validate TLS certificates, allowing an attacker with appropriate network access to obtain session tokens and sensitive information.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article