Impact
The flaw causes the mobile application to write the Cloud sync bearer token and the WebDAV password to unencrypted AsyncStorage under the keys @mindwtr_cloud_token and @mindwtr_webdav_password. An adversary who can read the application database or obtain a device backup can recover these credentials and gain unauthorized access to the user's synchronized tasks and attachments, effectively allowing data leakage and potential session hijacking.
Affected Systems
The vulnerability affects the Mindwtr mobile application of the vendor dongdongbh, specifically all releases prior to version 1.1.5. Users running these earlier releases should consider their mobile devices, backups, and any local storage as potential vectors for credential compromise.
Risk and Exploitability
The CVSS score is 4.4, indicating moderate severity, yet the EPSS score is not available, leaving the exact exploit probability uncertain. The vulnerability is not listed in the CISA KEV catalog. Attackers need local device access or the ability to access an exposed backup; from there the plaintext token and password are immediately usable to authenticate to the user’s task synchronization services and WebDAV endpoint.
OpenCVE Enrichment