GHSA-m335-63m5-3fhmLowCVSS 4.4
A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the...
🔗 CVE IDs covered (1)
📋 Description
A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the function com.airasia.core.utils.RealPathUtil.getRealPath of the component com.airasia.mobile. Performing a manipulation of the argument _display_name results in path traversal. The attack requires a local approach. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2026-84431
- https://docs.google.com/document/d/19qRCn6NWF2UE4urLXMXKgW555PHhnQiw/edit?usp=sharing&ouid=100768766778062598194&rtpof=true&sd=true
- https://vuldb.com/cve/CVE-2026-84431
- https://vuldb.com/submit/884138
- https://vuldb.com/vuln/397798
- https://vuldb.com/vuln/397798/cti
- https://github.com/advisories/GHSA-m335-63m5-3fhm