This advisory details a directory traversal vulnerability in Album Lock v4.0 iOS, allowing unauthorized file access via the `filePaht` parameter in the `getObject` endpoint. The PoC demonstrates path manipulation to access files outside the intended directory.
Classification
Writeup 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target:Album Lock v4.0 iOS
No auth needed
Prerequisites:Network access to the vulnerable iOS device's web server