First published: Fri Oct 22 2021(Updated: )
Swift File Transfer Mobile v1.1.2 and below was discovered to contain an information disclosure vulnerability in the path parameter. This vulnerability is exploited via an error caused by including non-existent path environment variables.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Swiftfiletransfer | <=1.0.19 | |
Swiftfiletransfer | <=1.1.2 | |
Swiftfiletransfer | <=1.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-23038 has been classified as a medium severity vulnerability due to its potential for information disclosure.
To remediate CVE-2020-23038, update Swift File Transfer Mobile to version 1.1.3 or later where the vulnerability has been addressed.
CVE-2020-23038 affects Swift File Transfer Mobile version 1.1.2 and below on Android and iPhone OS, as well as version 1.0.19 and lower on Blackberry.
CVE-2020-23038 is an information disclosure vulnerability that arises from improper handling of the path parameter.
CVE-2020-23038 can be exploited by including non-existent path environment variables, leading to exposure of sensitive information.