CVE Details
Basic Information
| Title | Boquan DotWallet App com.boquanhash.dotwallet AndroidManifest.xml improper export of android application components |
|---|---|
| Type | cve |
| Published | 2025-08-04T20:02:05.674Z |
| Modified | 2025-08-04T20:17:54.897Z |
Product Information
| Vendor | Boquan |
|---|---|
| Product | DotWallet App |
| Version | 2.15.2 |
CVSS Information
| Base Score | 4.8 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P |
AI Analysis
| AI Description | A vulnerability in the AndroidManifest.xml file of the Boquan DotWallet App allows improper export of application components, potentially exposing sensitive functionalities. |
|---|---|
| AI Severity | Medium |
| AI Vendor | Boquan |
| AI Product | DotWallet App |
| AI Version | 2.15.2 |
Affected Products
- Boquan DotWallet App 2.15.2
Additional Information
| CWE List | CWE-926 |
|---|---|
| Source | VulDB |
Description
A vulnerability was found in Boquan DotWallet App 2.15.2 on Android and classified as problematic. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.boquanhash.dotwallet. The manipulation leads to improper export of android application components. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.