Description
The "Photo,Video Locker-Calculator" application 12.0 for Android has android:allowBackup="true" in AndroidManifest.xml, which allows attackers to obtain sensitive cleartext information via an "adb backup '-f smart.calculator.gallerylock'" command.
References (1)
Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.ds-security.com/2017/11/16/photovideo-locker-calculator-leak-of-sensitive-files/
Scores
CVSS v3
7.5
EPSS
0.0067
EPSS Percentile
46.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-312
Status
published
Products (1)
photo\,video_locker-calculator_project/photo\,video_locker-calculator
12.0
Published
Feb 20, 2018
Tracked Since
Feb 18, 2026