VDB

CVE-2023-41387

CVE-2023-41387 PUBLISHED CVSS 9.100000381469727 CRITICAL

A SQL injection in the flutter_downloader component through 1.11.1 for iOS allows remote attackers to steal session tokens and overwrite arbitrary files inside the app's container. The internal database of the framework is exposed to the local user if an app uses UIFileSharingEnabled and LSSupportsOpeningDocumentsInPlace properties. As a result, local users can obtain the same attack primitives as remote attackers by tampering with the internal database of the framework on the device.

EPSS 0.65% · 49.7th percentile

Risk Scores

CVSS 3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS Score
0.65%
49.7th percentile

Affected Products

VendorProductVersions
n/an/an/a
patreonflutter_downloader0
patreonflutter_downloader0

Timeline

  • Sep 19, 2023 CVE Published
  • Sep 19, 2023 EPSS Score
  • Oct 22, 2023 EPSS Score
  • Nov 23, 2023 EPSS Score
  • Dec 26, 2023 EPSS Score
  • Jan 27, 2024 EPSS Score
  • Feb 29, 2024 EPSS Score
  • Apr 2, 2024 EPSS Score
  • May 4, 2024 EPSS Score
  • Jun 6, 2024 EPSS Score
  • Jul 9, 2024 EPSS Score
  • Aug 10, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›