Impact
Squareapps My Location Travel Timeline v11.80 contains an arbitrary file overwrite flaw that allows an attacker to replace critical internal files during the file import process. Because the overwrite can target executable binaries or configuration files, the attacker can inject malicious code or otherwise alter runtime behavior, resulting in arbitrary code execution or exposure of sensitive data.
Affected Systems
The vulnerability impacts Squareapps My Location Travel Timeline for Android, specifically version 11.80. Users of this release are at risk when they use the file import feature within the application.
Risk and Exploitability
The flaw carries a CVSS score of 8.4, indicating high severity, and an EPSS score of less than 1%, implying a low current exploitation probability. It is not listed in the CISA KEV catalog. The likely attack vector is through the file import process, which probably requires local device access; remote exploitation is not explicitly documented. Once exploited, an attacker could execute arbitrary code or exfiltrate data.
OpenCVE Enrichment