CVE-2021-47972

HIGH

Sticky Notes & Color Widgets 1.4.2 Denial of Service

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-47972. PoCs published by Geovanni Ruiz.

AI-analyzed exploit summary The exploit demonstrates a Denial of Service (DoS) vulnerability in Sticky Notes & Color Widgets 1.4.2 by generating a large payload (350,000 'A' characters) that crashes the application when pasted into a note. The PoC includes a Python script to create the payload file and steps to reproduce the crash.

Description

Sticky Notes & Color Widgets 1.4.2 contains a denial of service vulnerability that allows attackers to crash the application by creating notes with excessively long character strings. Attackers can paste large payloads of repeated characters into note fields to trigger application crashes and make the application stop responding.

Exploits (1)

exploitdb WORKING POC
by Geovanni Ruiz · pythondosios
https://www.exploit-db.com/exploits/49957

The exploit demonstrates a Denial of Service (DoS) vulnerability in Sticky Notes & Color Widgets 1.4.2 by generating a large payload (350,000 'A' characters) that crashes the application when pasted into a note. The PoC includes a Python script to create the payload file and steps to reproduce the crash.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Sticky Notes & Color Widgets 1.4.2
No auth needed
Prerequisites: Access to the target iOS device · Ability to run the Python script to generate the payload · Ability to paste the payload into the application
devstral-2 · analyzed May 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit exploit
ExploitDB-49957
https://www.exploit-db.com/exploits/49957
Third Party Advisory third-party-advisory
VulnCheck Advisory: Sticky Notes & Color Widgets 1.4.2 Denial of Service
https://www.vulncheck.com/advisories/sticky-notes-color-widgets-denial-of-service

Scores

CVSS v3 7.5
EPSS 0.0028
EPSS Percentile 19.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-789
Status published
Products (1)
sticky-notes-color-widgets/Sticky Notes Color Widgets 1.4.2
Published May 16, 2026
Tracked Since May 16, 2026