PT-2024-33723 · Transsion · Com.Transsion.Videocallenhancer

·

CVE-2024-4988

·

Published

2024-05-21

·

Updated

2024-08-21

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: com.transsion.videocallenhancer version 1.1.9.973
Description: The mobile application interface has improper permission control, which can lead to the risk of private file leakage. This issue can result in unauthorized access to private files.
Recommendations: For version 1.1.9.973, update the app immediately and review file permissions to mitigate the risk of private file leakage. As a temporary workaround, consider restricting access to sensitive files until the issue is resolved.

Fix

Improper Access Control

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-4988

Affected Products

Com.Transsion.Videocallenhancer