Vulnerabilities (CVE)

Filtered by vendor Omninotes
Filtered by product Omni Notes
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-33188 1 Omninotes 1 Omni Notes 2024-11-21 N/A 6.3 MEDIUM
Omni-notes is an open source note-taking application for Android. The Omni-notes Android app had an insufficient path validation vulnerability when displaying the details of a note received through an externally-provided intent. The paths of the note's attachments were not properly validated, allowing malicious or compromised applications in the same device to force Omni-notes to copy files from its internal storage to its external storage directory, where they would have become accessible to an ...

Show More