An issue was discovered in the Boomerang Parental Control application before 13.83 for Android. The app is missing the android:allowBackup=false attribute in the manifest. This allows the user to backup the internal memory of the app to a PC. This gives the user access to the API token that is used to authenticate requests to the API.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Boomerang | Nationaledtech | * | 13.83 (excluding) |