Executive brief
The Ataturk University ATA-AOF mobile application, used by students for distance learning services, contains critical security flaws. These vulnerabilities allow unauthorized individuals to bypass login requirements and access sensitive user information or administrative functions. This could lead to widespread account takeovers and the exposure of personal student data.
Technical details
The ATA-AOF mobile application is vulnerable to authentication bypass and abuse due to two primary flaws: the use of hard-coded credentials (CWE-798) and the transmission of sensitive information in cleartext (CWE-319). An unauthenticated remote attacker can exploit these weaknesses to gain unauthorized access to the application's backend or user accounts without providing valid credentials. The vulnerability is rated with a CVSS 10.0 due to the lack of required privileges and the high impact on confidentiality and integrity. Users are advised to update to versions released after June 20, 2025.
Affected products
- Ataturk University ATA-AOF Mobile Application before 20.06.2025
Timeline
- 2025-06-24: advisory: NVD publication date
- 2025-06-20: patched: Versions before this date are affected