Security Advisory

CVE-2019-13096

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-07-22 16:14:26
Last updated 2024-08-04 23:41:10
Assigner mitre
State PUBLISHED

Description

TronLink Wallet 2.2.0 stores user wallet keystore in plaintext and places them in insecure storage. An attacker can read and reuse the user keystore of a valid user via /data/data/com.tronlink.wallet/shared_prefs/<wallet-name>.xml to gain unauthorized access.