An issue in simplemobiletools Simple Dialer 5.18.1 allows an attacker to bypass intended access restrictions via interaction with com.simplemobiletools.dialer.activities.DialerActivity.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://github.com/actuator/com.simplemobiletools.dialer/blob/main/CWE-928.md | exploit |
https://github.com/actuator/cve/blob/main/CVE-2023-49003 | third party advisory |