Jack Sessions

2 exploits Active since Aug 2025
CVE-2025-50861 WRITEUP MEDIUM WRITEUP
Lotus Cars Android app 1.2.8 - SSRF
The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 contains an exported component, PushDeepLinkActivity, which is accessible without authentication via ADB or malicious apps. This poses a risk of unintended access to application internals and can cause denial of service or logic abuse.
CVSS 6.5
CVE-2025-50862 WRITEUP MEDIUM WRITEUP
Lotus Cars Android app <1.2.8 - Info Disclosure
The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 has allowBackup=true set in its manifest, allowing data exfiltration via ADB backup on rooted or debug-enabled devices. This presents a risk of user data exposure.
CVSS 5.9