vendor:
Air Transfer
by:
Samandeep Singh
7.5
CVSS
HIGH
Remote Application Crashing
400
CWE
Product Name: Air Transfer
Affected Version From: 1.3.2009
Affected Version To: 1.3.2009
Patch Exists: NO
Related CWE:
CPE: a:darinsoft:air_transfer:1.3.9
Platforms Tested: iOS
2014
Air Transfer Iphone v1.3.9 -Remote crash, Broken Authentication file download and Memo Access.
The vulnerability allows an attacker to crash the Air Transfer application by sending a specially crafted GET request to the getList endpoint.
Mitigation:
The vendor has not provided a patch or fix for this vulnerability. Users are advised to avoid using the Air Transfer application or to update to a newer version if available.