Impact
The vulnerability resides in the Docx Reader Office Viewer App's document processing function, where manipulation of the _display_name argument allows a crafted request to open arbitrary files outside the intended directory limits. The effect is that an attacker can read sensitive files from the device’s file system or potentially force the application to read files it normally would not be able to access. The weakness is a classic directory traversal flaw (CWE‑22) and the impact is restricted to confidentiality, with no direct integrity or availability damage reported. The description indicates the attack can be performed remotely via the network interface that the application exposes.
Affected Systems
The flaw affects Lippu Docx Reader Office Viewer App on Android devices with versions up to 1.4.5. No later versions were mentioned, and the fixed release (if any) was not specified in the advisory. Users of the affected builds should verify the version deployed on their devices and seek an updated package if available.
Risk and Exploitability
The CVSS base score of 5.3 places the issue in the moderate range. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting that large‑scale exploitation is not documented. Nevertheless, the attack vector is remote, so the potential for exploitation exists, especially if the application is exposed to untrusted network traffic. The absence of additional mitigation notes means that, unless the app employs defensive checks internally, the risk remains moderate to high in environments where malicious input can be injected.
OpenCVE Enrichment