Description
An issue was discovered in the Boomerang Parental Control application before 13.83 for Android. The app is missing the android:allowBackup="false" attribute in the manifest. This allows the user to backup the internal memory of the app to a PC. This gives the user access to the API token that is used to authenticate requests to the API.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-40564 | An issue was discovered in the Boomerang Parental Control application before 13.83 for Android. The app is missing the android:allowBackup="false" attribute in the manifest. This allows the user to backup the internal memory of the app to a PC. This gives the user access to the API token that is used to authenticate requests to the API. |
References
History
Thu, 05 Sep 2024 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-05T15:03:54.184Z
Reserved: 2023-06-25T00:00:00.000Z
Link: CVE-2023-36620
Updated: 2024-08-02T16:52:54.055Z
Status : Modified
Published: 2023-11-03T04:15:21.023
Modified: 2024-11-21T08:10:05.420
Link: CVE-2023-36620
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD