Able to intercept app Traffic after choosing up the Secured Connection using SSL (HTTPS)

Disclosed: 2017-03-03 14:21:12 By bugwrangler To vkcom
Unknown
Vulnerability Details
Install the app Login with Valid credentials Settings - Choose Secured connection (HTTPS) Close the app Set the proxy and Open the app verify that Connection isn't Secured and able to intercept (PFA POC) Expected Result : Secured layer & SSL PINING should be applied successfully.
Actions
View on HackerOne
Report Stats
  • Report ID: 64731
  • State: Closed
  • Substate: resolved
  • Upvotes: 4
Share this report