Loading HuntDB...

App PIN code can be bypassed in Files iOS

Low
N
Nextcloud
Submitted None

Team Summary

Official summary from Nextcloud

Security advisory at https://github.com/nextcloud/security-advisories/security/advisories/GHSA-j8g7-88vv-rggv

Reported by spell1

Vulnerability Details

Technical details and impact analysis

Improper Authentication - Generic
Hi Team, Hope you are doing great. Note: IoS APP Vs.: 4.9.1 I got a vulnerability in your applications via which an attacker is able to bypass the PIN. The attacker just need to bruteforce the 4 digit PIN as unlimited tries is accepted by the application, the attacker can simply do a bruteforce and access the application. PoC: {F2844276} ## Impact Authentication Bypass leading to application access

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Authentication - Generic