Security Advisory
CVE-2023-36612
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Directory traversal can occur in the Basecamp com.basecamp.bc3 application before 4.2.1 for Android, which may allow an attacker to write arbitrary files in the applications private directory. Additionally, by using a malicious intent, the attacker may redirect the servers responses (containing sensitive information) to third-party applications by using a custom-crafted deeplink scheme.