Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Metaclassy Byword app 2.x before 2.1 for iOS does not require confirmation of Replace file actions, which allows remote attackers to overwrite arbitrary files via the name and text parameters in a byword://replace URL.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Metaclassy Byword应用程序权限许可和访问控制漏洞
Vulnerability Description
Metaclassy Byword是葡萄牙Metaclassy公司的一套用于Mac、iPhone、iPad设备上的文字编辑软件。 iOS平台下的Metaclassy Byword应用程序2.0.0至2.0.3版本中存在安全漏洞,该漏洞源于程序未要求对替换文件操作进行确认。远程攻击者可借助byword://replace URL中的name和text参数利用该漏洞覆盖任意文件。
CVSS Information
N/A
Vulnerability Type
N/A