In net.MCrypt in the "Diary with lock" (aka WriteDiary) application 4.72 for Android, hardcoded SecretKey and iv variables are used for the AES parameters, which makes it easier for malicious users to obtain the cleartext of stored diary entries.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
writediary diary with lock 4.72 |