PT-2023-22384 · Unknown · Lock Master
Published
2023-05-30
·
Updated
2025-01-14
·
CVE-2023-29733
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The Lock Master app version 2.2.4
Description
The issue allows unauthorized apps to modify the values in the SharedPreference files of the Lock Master app. These files hold data that affects many app functions. Malicious modifications by unauthorized apps can cause security issues, such as functionality manipulation, resulting in a severe escalation of privilege attack.
Recommendations
For version 2.2.4, consider restricting access to the SharedPreference files until a patch is available. As a temporary workaround, review and monitor the app's functionality regularly to detect any potential malicious modifications. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lock Master