CVE Vulnerabilities

CVE-2013-5725

Published: Oct 01, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Metaclassy Byword app 2.x before 2.1 for iOS does not require confirmation of Replace file actions, which allows remote attackers to overwrite arbitrary files via the name and text parameters in a byword://replace URL.

Affected Software

NameVendorStart VersionEnd Version
BywordMetaclassy2.0.0 (including)2.0.0 (including)
BywordMetaclassy2.0.1 (including)2.0.1 (including)
BywordMetaclassy2.0.2 (including)2.0.2 (including)
BywordMetaclassy2.0.3 (including)2.0.3 (including)

References