The Photo,Video Locker-Calculator application 12.0 for Android has android:allowBackup=true in AndroidManifest.xml, which allows attackers to obtain sensitive cleartext information via an adb backup -f smart.calculator.gallerylock command.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Photo,video_locker-calculator | Photo,video_locker-calculator_project | 12.0 (including) | 12.0 (including) |