CVE-2023-36620 affects the Boomerang Parental Control application for Android (versions prior to 13.83). The vulnerability stems from a missing "android:allowBackup='false'" attribute, enabling users to back up the app's internal memory to a PC. This medium-severity flaw (CVSS 4.6) allows unauthorized access to the API token, potentially compromising authentication. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 13.83CPE matchmatch criteria | cpe:2.3:a:nationaledtech:boomerang:*:*:*:*:*:android:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.