vendor:
Folder Plus
by:
Vulnerability Laboratory Research Team
3,5
CVSS
MEDIUM
Persistent Input Validation Web Vulnerability
79
CWE
Product Name: Folder Plus
Affected Version From: 2.5.1
Affected Version To: 2.5.1
Patch Exists: NO
Related CWE: N/A
CPE: a:theverygames:folder_plus:2.5.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: iOS
2014
Folder Plus v2.5.1 iOS – Persistent Item Vulnerability
A persistent input validation web vulnerability has been discovered in the official Folder Plus v2.5.1 iOS mobile application. The issue allows an attacker to inject own script code as payload to the application-side of the vulnerable service function or module. The vulnerability is located in the delete item message context of the wifi interface listing module. The issue allows rmt attacker to inject own malicious script code as payload to the application-side of the vulnerable service function.
Mitigation:
Input validation should be used to detect unauthorized input before it is processed by the application.