com.nextcloud.client bypass the protection lock in andoid app v 3.18.1 latest version.
Low
Vulnerability Details
## Summary:
nextcloud allowed multiple account within the android client app on a single lock
## Steps To Reproduce:
1.open nextcloud app
2.add security password to protect the app
3.close the app
again open the app and now show the password to open the app
1. so now the password protection bypass lets start
2.hold the nextcloud app and see the app info open it
3.Here the three option 1.open.2.uninstall and 3.force stop
now click open button and now see the app lock protection in the app and now open app and back open and back between 3 to 4 time
same procedure and now you will see the app lock protection bypass in nextcloud android app
## Supporting Material/References:
[list any additional material (e.g. screenshots, logs, etc.)]
* [attachment / reference]
## Impact
if an attacker has physical access to an android mobile without screen lock,but with nextcloud installed and set up,he can easily access the nextcloud-files.
regards:Javed Ahmad
Actions
View on HackerOneReport Stats
- Report ID: 1450368
- State: Closed
- Substate: resolved
- Upvotes: 8