S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-27587 Scanner

CVE-2023-27587 scanner - Information Disclosure vulnerability in ReadtoMyShoe

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-27587
6.5
CVSShigh
Exploitable remotely over the internet · no authentication required · user interaction needed.

ReadtoMyShoe, a web app that lets users upload articles and listen to them later, generates an error message containing sensitive information prior to commit 8533b01. If an error occurs when adding an article, the website shows the user an error message. If the error originates from the Google Cloud TTS request, then it will include the full URL of the request. The request URL contains the Google Cloud API key. This has been patched in commit 8533b01. Upgrading should be accompanied by deleting the current GCP API key and issuing a new one. There are no known workarounds.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
readtomyshoeby rozbb
<= 0.2.0
Updated Aug 22, 2026View on NVD →
Detail

ReadtoMyShoe is a web app designed to make life easier for those who like to read articles but don't have the time to do so. The app allows users to upload articles, and then listen to them later at their convenience. The use of the app is straightforward: users upload articles to the app and click play when they're ready to listen to them.

However, the app was recently discovered to have a severe vulnerability, CVE-2023-27587, which could compromise users' safety and privacy. This security flaw was detected in the app prior to commit 8533b01. When users attempted to add an article, they were shown an error message. If this error message originated from the Google Cloud TTS request, then it would include the full URL of the request. The request URL contained the Google Cloud API key, which could be accessed by anyone who saw the error message.

The exploitation of this vulnerability could result in personal data and sensitive information being stolen, as well as malicious actors gaining access to users' Google Cloud accounts. This could lead to serious consequences, from identity theft to financial fraud. The vulnerability is particularly dangerous because users who encounter an error message that includes the request URL may not realize that their sensitive information has been compromised.

In conclusion, if you're concerned about vulnerabilities in your digital assets, the pro features of the s4e.io platform can help you learn about them quickly and easily. With features like vulnerability scanning and continuous monitoring, you can be sure that your digital assets are protected against any potential threats. By taking advantage of these features, you can rest assured that your digital assets are protected against all vulnerabilities, including the recently discovered CVE-2023-27587 vulnerability in ReadtoMyShoe.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users should follow the following precautions in their use of ReadtoMyShoe:

  • Upgrade to commit 8533b01 or newer.
  • Delete the current GCP API key and replace with a new one.
  • Avoid using the app until it has been upgraded and the new API key has been issued.
  • Be wary of error messages that include the full URL of the Google Cloud TTS request.
  • Monitor accounts for any suspicious activity, such as unauthorized access to Google Cloud services.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.