CVE-2019-13100

Severity CVSS v4.0:
Pending analysis
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
22/07/2019
Last modified:
24/08/2020

Description

The Send Anywhere application 9.4.18 for Android stores confidential information insecurely on the system (i.e., in cleartext), which allows a non-root user to find out the username/password of a valid user via /data/data/com.estmob.android.sendanywhere/shared_prefs/sendanywhere_device.xml.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:send-anywhere:send_anywhere:9.4.18:*:*:*:*:android:*:*


References to Advisories, Solutions, and Tools