Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Dialogue App ca.diagram.dialogue config.json hard-coded key
Vulnerability Description
A vulnerability was determined in Dialogue App up to 4.3.2 on Android. The affected element is an unknown function of the file file res/raw/config.json of the component ca.diagram.dialogue. Executing a manipulation of the argument SEGMENT_WRITE_KEY can lead to use of hard-coded cryptographic key . The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
使用硬编码的密码学密钥
Vulnerability Title
Dialogue App 安全漏洞
Vulnerability Description
Dialogue App是Dialogue公司的一个人工智能对话应用。 Dialogue App 4.3.2及之前版本存在安全漏洞,该漏洞源于对参数SEGMENT_WRITE_KEY使用硬编码加密密钥。
CVSS Information
N/A
Vulnerability Type
N/A