vendor:
Bookeen Notea
by:
Clement MAILLIOUX
8.8
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Bookeen Notea
Affected Version From: BK_R_1.0.5_20210608
Affected Version To: BK_R_1.0.5_20210608
Patch Exists: YES
Related CWE: CVE 2021-45783
CPE: a:bookeen:bookeen_notea
Platforms Tested: Android 8.1
2021
Bookeen Notea – Directory Traversal
The affected version of the Bookeen Notea System Update is prone to directory traversal vulnerability related to its note Export function. The vulnerability can be triggered by creating a note or using an existing note on the device, renaming it to '../../../../../../', and then selecting 'export' and 'View' from the menu that appears. This allows access and exploration of the device filesystem.
Mitigation:
Ensure that the system is updated to the latest version of the Bookeen Notea System Update.