Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Kyivstarteam

#48176of 53,630
5.3Total CVSS
Vulnerabilities · 1
PT-2024-11036
5.3
2024-04-07
Kyivstarteam · React-Native-Sms-User-Consent · CVE-2021-4438
**Name of the Vulnerable Software and Affected Versions** kyivstarteam react-native-sms-user-consent versions 1.1.4 and earlier **Description** A critical issue has been found in the affected software, specifically in the function `registerReceiver` of the file `android/src/main/java/ua/kyivstar/reactnativesmsuserconsent/SmsUserConsentModule.kt`. This issue leads to improper export of Android application components. It requires a local attack to be exploited. **Recommendations** To address this issue, upgrade to version 1.1.5. As a temporary workaround, consider disabling the `registerReceiver` function until the patch is applied. Restrict access to the `SmsUserConsentModule.kt` file to minimize the risk of exploitation.