Lucene search

K
cveMitreCVE-2023-36612
HistoryJun 25, 2023 - 3:15 a.m.

CVE-2023-36612

2023-06-2503:15:46
CWE-22
mitre
web.nvd.nist.gov
17
cve-2023-36612
directory traversal
basecamp
android
security vulnerability
application security
deeplink scheme
nvd

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

25.0%

Directory traversal can occur in the Basecamp com.basecamp.bc3 application before 4.2.1 for Android, which may allow an attacker to write arbitrary files in the application’s private directory. Additionally, by using a malicious intent, the attacker may redirect the server’s responses (containing sensitive information) to third-party applications by using a custom-crafted deeplink scheme.

Affected configurations

Nvd
Node
basecampbasecampRange<4.2.1android
VendorProductVersionCPE
basecampbasecamp*cpe:2.3:a:basecamp:basecamp:*:*:*:*:*:android:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

25.0%

Related for CVE-2023-36612