CVE detail
CVE-2019-13098 — CVE-2019-13098
Published 2019-07-22 · Modified 2026-06-17 · Vendor tronlink · Product wallet · Source nvd
MEDIUM
severity
CVSS-derived band
0.0134
EPSS probability
exploitation probability, 30d
69.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The user password via the registration form of TronLink Wallet 2.2.0 is stored in the log when the class CreateWalletTwoActivity is called. Other authenticated users can read it in the log later. The logged data can be read using Logcat on the device. When using platforms prior to Android 4.1 (Jelly Bean), the log data is not sandboxed per application; any application installed on the device has the capability to read data logged by other applications.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References