Impact
The vulnerability resides in Blix Email Blue Mail Calendar App’s FileDirectory.getFileFromUri method, where the _display_name parameter can be manipulated to perform a path traversal attack. The flaw falls under CWE‑22 and enables an attacker with local access to read or expose files outside the intended storage area, potentially revealing sensitive data. As the attack vector is limited to devices where the compromised app is installed, the impact is confined to the local user’s device data and confidentiality is at risk.
Affected Systems
Blix; Email Blue Mail Calendar App; version 2.2.305. No other product or version information is provided.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, and the EPSS score is not available, but the vulnerability is publicly exploited. The exploit requires local access, meaning it does not pose a remote attack risk. It is not listed in the CISA KEV catalog, but the public availability of the exploit warrants caution. The risk level is moderate because local compromise is needed, yet the potential for sensitive file disclosure on the device makes it a significant concern for affected users.
OpenCVE Enrichment