Improper Neutralization of Argument Delimiters in a Decompiling Package Process in APKLeaks
Critical severity
GitHub Reviewed
Published
Mar 19, 2021
in
dwisiswant0/apkleaks
•
Updated Sep 7, 2023
Description
Published by the National Vulnerability Database
Mar 24, 2021
Reviewed
Jan 21, 2022
Published to the GitHub Advisory Database
Jan 21, 2022
Last updated
Sep 7, 2023
APKLeaks prior to v2.0.4 allows remote authenticated attackers to execute arbitrary OS commands via package name inside the application manifest.
Impact
An authenticated attacker could include arguments that allow unintended commands or code to be executed, allow sensitive data to be read or modified, or could cause other unintended behavior through malicious package names.
References
For more information
If you have any questions or comments about this advisory:
References