Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16246 | A vulnerability, which was classified as problematic, was found in PhonePe App 25.03.21.0 on Android. Affected is an unknown function of the file /data/data/com.phonepe.app/databases/ of the component SQLite Database. The manipulation leads to cleartext storage in a file or on disk. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. |
Tue, 03 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Phonepe
Phonepe phonepe |
|
| CPEs | cpe:2.3:a:phonepe:phonepe:25.03.21.0:*:*:*:*:android:*:* | |
| Vendors & Products |
Phonepe
Phonepe phonepe |
Wed, 28 May 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 25 May 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability, which was classified as problematic, was found in PhonePe App 25.03.21.0 on Android. Affected is an unknown function of the file /data/data/com.phonepe.app/databases/ of the component SQLite Database. The manipulation leads to cleartext storage in a file or on disk. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. | |
| Title | PhonePe App SQLite Database databases cleartext storage in a file or on disk | |
| Weaknesses | CWE-312 CWE-313 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-05-28T17:38:08.525Z
Reserved: 2025-05-24T22:19:52.467Z
Link: CVE-2025-5154
Updated: 2025-05-27T14:21:06.543Z
Status : Analyzed
Published: 2025-05-25T19:15:19.740
Modified: 2025-06-03T13:53:41.553
Link: CVE-2025-5154
No data.
OpenCVE Enrichment
No data.
EUVD