CVE-2017-15581

Severity CVSS v4.0:
Pending analysis
Type:
CWE-311 Missing Encryption of Sensitive Data
Publication date:
27/10/2017
Last modified:
20/04/2025

Description

In the "Diary with lock" (aka WriteDiary) application 4.72 for Android, neither HTTPS nor other encryption is used for transmitting data, despite the documentation that the product is intended for "a personal journal of ... secrets and feelings," which allows remote attackers to obtain sensitive information by sniffing the network during LoginActivity or NoteActivity execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:writediary:diary_with_lock:4.72:*:*:*:*:android:*:*