An issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data via the android:allowBackup=true in the ANdroidManifest.xml
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Kukufm | Kukufm | 1.12.7 (including) | 1.12.7 (including) |