App PIN code can be bypassed in Files iOS
Low
N
Nextcloud
Submitted None
Team Summary
Official summary from Nextcloud
Security advisory at https://github.com/nextcloud/security-advisories/security/advisories/GHSA-j8g7-88vv-rggv
Actions:
Reported by
spell1
Vulnerability Details
Technical details and impact analysis
Hi Team,
Hope you are doing great.
Note: IoS APP Vs.: 4.9.1
I got a vulnerability in your applications via which an attacker is able to bypass the PIN.
The attacker just need to bruteforce the 4 digit PIN as unlimited tries is accepted by the application, the attacker can simply do a bruteforce and access the application.
PoC:
{F2844276}
## Impact
Authentication Bypass leading to application access
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Authentication - Generic