PT-2023-15136 · Timmystudios · Timmystudios Fast Typing Keyboard

CVE-2022-47027

·

Publicado

2023-04-14

·

Atualizado

2025-02-07

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Timmystudios Fast Typing Keyboard version 1.275.1.162
Description The issue allows unauthorized apps to overwrite arbitrary files in the internal storage of Timmystudios Fast Typing Keyboard via a dictionary traversal vulnerability, which can lead to arbitrary code execution.
Recommendations For version 1.275.1.162, consider restricting access to the internal storage to prevent unauthorized overwrites until a patch is available. As a temporary workaround, avoid using the keyboard's internal storage for sensitive data until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-47027

Produtos afetados

Timmystudios Fast Typing Keyboard