PT-2025-3025 · Unknown · File Selector+1
Oskar-Zeinomahmalat-Sonarsource
·
Published
2025-01-29
·
Updated
2025-01-29
·
CVE-2024-54461
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
file selector versions prior to 0.5.1+12
file selector android versions prior to 0.5.1+12
Description
The file names constructed within file selector are missing sanitization checks, leaving them vulnerable to malicious document providers. This may result in cases where a user with a malicious document provider installed can select a document file from that provider while using their app and could potentially override internal files in their app cache.
Recommendations
For file selector versions prior to 0.5.1+12, update to the latest version of file selector android that contains the changes to address this vulnerability.
For file selector android versions prior to 0.5.1+12, update to version 0.5.1+12 or later to resolve the issue.
Fix
Path traversal
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
File Selector
File Selector Android