Home
MEDIUM: 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NDefault status
unknown
Any version
affected
Description
Unencrypted storage in the database in Two App Studio Journey v5.5.9 for iOS allows local attackers to extract sensitive data via direct access to the app’s filesystem.
Problem types
CWE-312 Cleartext Storage of Sensitive Information
Product status
Any version
Timeline
| 2025-03-12: | Vendor was contacted and informed about the vulnerability via email. |
| 2025-03-25: | Second attempt was made to contact vendor via email. |
| 2025-06-25: | Third attempt was made to contact vendor via email. |
Credits
Hannes Allmann (cirosec GmbH) <hannes.allmann@cirosec.de>
References
www.cirosec.de/sa/sa-2025-005