CVE-2020-11826

Severity CVSS v4.0:
Pending analysis
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
16/04/2020
Last modified:
21/07/2021

Description

Users can lock their notes with a password in Memono version 3.8. Thus, users needs to know a password to read notes. However, these notes are stored in a database without encryption and an attacker can read the password-protected notes without having the password. Notes are stored in the ZENTITY table in the memono.sqlite database.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:appinghouse:memono:3.8:*:*:*:*:iphone_os:*:*