PT-2020-12874 · Memono · Memono

Published

2020-04-16

·

Updated

2021-07-21

·

CVE-2020-11826

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Memono version 3.8
Description The issue allows an attacker to access password-protected notes without knowing the password. This is because the notes are stored in the database, specifically in the ZENTITY table of the memono.sqlite database, without encryption.
Recommendations For Memono version 3.8, consider encrypting the notes stored in the ZENTITY table of the memono.sqlite database to prevent unauthorized access. As a temporary workaround, restrict access to the memono.sqlite database to minimize the risk of exploitation.

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11826

Affected Products

Memono