CVE Vulnerabilities

CVE-2013-5725

Published: Oct 01, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io minimus.io echohq.com

The Metaclassy Byword app 2.x before 2.1 for iOS does not require confirmation of Replace file actions, which allows remote attackers to overwrite arbitrary files via the name and text parameters in a byword://replace URL.

Affected Software

Name Vendor Start Version End Version
Byword Metaclassy 2.0.0 (including) 2.0.0 (including)
Byword Metaclassy 2.0.1 (including) 2.0.1 (including)
Byword Metaclassy 2.0.2 (including) 2.0.2 (including)
Byword Metaclassy 2.0.3 (including) 2.0.3 (including)

References