CVE-2024-49421
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
03/12/2024
Last modified:
24/09/2025
Description
Path traversal in Quick Share Agent prior to version 3.5.14.47 in Android 12, 3.5.19.41 in Android 13, and 3.5.19.42 in Android 14 allows adjacent attackers to write file in arbitrary location.
Impact
Base Score 3.x
4.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:samsung:quick_share:*:*:*:*:*:*:*:* | 3.5.19.41 (excluding) | |
| cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:samsung:quick_share:*:*:*:*:*:*:*:* | 3.5.19.42 (excluding) | |
| cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:samsung:quick_share:*:*:*:*:*:*:*:* | 3.5.14.47 (excluding) | |
| cpe:2.3:o:google:android:12.0:-:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



