Home

Description

Kanova Android App version 1.0.27 (package name com.karelane), developed by Karely L.L.C., contains improper access control vulnerabilities. Attackers may gain unauthorized access to user details and obtain group information, including entry codes, by manipulating API request parameters. Successful exploitation could result in privacy breaches, unauthorized group access, and misuse of the platform.

PUBLISHED Reserved 2025-09-26 | Published 2025-10-30 | Updated 2025-10-30 | Assigner mitre

References

kar1oz.notion.site/Kanova-2629a473ecb2801bac89ce99d0b30df7

cve.org (CVE-2025-61119)

nvd.nist.gov (CVE-2025-61119)

Download JSON