Vulnerability Description
Users can lock their notes with a password in Memono version 3.8. Thus, users needs to know a password to read notes. However, these notes are stored in a database without encryption and an attacker can read the password-protected notes without having the password. Notes are stored in the ZENTITY table in the memono.sqlite database.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Appinghouse | Memono | 3.8 |
Related Weaknesses (CWE)
References
- https://fatihhcelik.blogspot.com/2020/02/memono-insecure-data-storage-ios.htmlThird Party Advisory
- https://fatihhcelik.blogspot.com/2020/02/memono-insecure-data-storage-ios.htmlThird Party Advisory
FAQ
What is CVE-2020-11826?
CVE-2020-11826 is a vulnerability with a CVSS score of 7.5 (HIGH). Users can lock their notes with a password in Memono version 3.8. Thus, users needs to know a password to read notes. However, these notes are stored in a database without encryption and an attacker c...
How severe is CVE-2020-11826?
CVE-2020-11826 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-11826?
Check the references section above for vendor advisories and patch information. Affected products include: Appinghouse Memono.