VDB
CVE-2023-41387
CVE-2023-41387
PUBLISHED
CVSS 9.100000381469727 CRITICAL
A SQL injection in the flutter_downloader component through 1.11.1 for iOS allows remote attackers to steal session tokens and overwrite arbitrary files inside the app's container. The internal database of the framework is exposed to the local user if an app uses UIFileSharingEnabled and LSSupportsOpeningDocumentsInPlace properties. As a result, local users can obtain the same attack primitives as remote attackers by tampering with the internal database of the framework on the device.
EPSS 0.65% · 49.7th percentile
Risk Scores
CVSS 3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS Score
0.65%
49.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| patreon | flutter_downloader | 0 |
| patreon | flutter_downloader | 0 |
Timeline
- Sep 19, 2023 CVE Published
- Sep 19, 2023 EPSS Score
- Oct 22, 2023 EPSS Score
- Nov 23, 2023 EPSS Score
- Dec 26, 2023 EPSS Score
- Jan 27, 2024 EPSS Score
- Feb 29, 2024 EPSS Score
- Apr 2, 2024 EPSS Score
- May 4, 2024 EPSS Score
- Jun 6, 2024 EPSS Score
- Jul 9, 2024 EPSS Score
- Aug 10, 2024 EPSS Score