Home

Description

Unencrypted storage in the database in Two App Studio Journey v5.5.9 for iOS allows local attackers to extract sensitive data via direct access to the app’s filesystem.

PUBLISHED Reserved 2025-04-16 | Published 2025-07-21 | Updated 2025-07-21 | Assigner cirosec




MEDIUM: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Problem types

CWE-312 Cleartext Storage of Sensitive Information

Product status

Default status
unknown

Any version
affected

Timeline

2025-03-12:Vendor was contacted and informed about the vulnerability via email.
2025-03-25:Second attempt was made to contact vendor via email.
2025-06-25:Third attempt was made to contact vendor via email.

Credits

Hannes Allmann (cirosec GmbH) <hannes.allmann@cirosec.de> finder

References

www.cirosec.de/sa/sa-2025-005 third-party-advisory

cve.org (CVE-2025-41458)

nvd.nist.gov (CVE-2025-41458)

Download JSON