PT-2023-22377 · Unknown · Bt21 X Bts Wallpaper
Published
2023-06-02
·
Updated
2025-01-08
·
CVE-2023-29725
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
BT21 x BTS Wallpaper app version 12 for Android
Description
The issue allows unauthorized applications to request permission to insert data into the database that records user personal preferences. This data is loaded into memory when the application is opened. By injecting data, an attacker can force the application to load malicious image URLs and display them in the UI. As the amount of data increases, it will cause the application to trigger an OOM error and crash, resulting in a persistent denial of service attack.
Recommendations
For BT21 x BTS Wallpaper app version 12, consider restricting access to the database that records user personal preferences to prevent unauthorized data injection until a patch is available. As a temporary workaround, avoid using the application with unauthorized permissions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bt21 X Bts Wallpaper