The mixi application before 4.3.0 for Android allows remote attackers to read potentially sensitive information in friends' comments via a crafted application that leverages the storage of these comments on an SD card.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://jvndb.jvn.jp/jvndb/JVNDB-2012-000078 | third party advisory |
http://jvn.jp/en/jp/JVN92038939/index.html | third party advisory |