We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Unencrypted storage in the database in Two App Studio Journey v5.5.9 for iOS allows local attackers to extract sensitive data via direct access to the app’s filesystem.
Reserved 2025-04-16 | Published 2025-07-21 | Updated 2025-07-21 | Assigner cirosecCWE-312 Cleartext Storage of Sensitive Information
2025-03-12: | Vendor was contacted and informed about the vulnerability via email. |
2025-03-25: | Second attempt was made to contact vendor via email. |
2025-06-25: | Third attempt was made to contact vendor via email. |
Hannes Allmann (cirosec GmbH) <hannes.allmann@cirosec.de>
www.cirosec.de/sa/sa-2025-005
Support options