{ "schema_version": "1.4.0", "id": "GHSA-f329-5h54-9xp6", "modified": "2022-05-24T17:37:39Z", "published": "2022-05-24T17:37:39Z", "aliases": [ "CVE-2020-35173" ], "details": "The Amaze File Manager application before 3.4.2 for Android does not properly restrict intents for controlling the FTP server (aka services.ftpservice.FTPReceiver.ACTION_START_FTPSERVER and services.ftpservice.FTPReceiver.ACTION_STOP_FTPSERVER).", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35173" }, { "type": "WEB", "url": "https://github.com/TeamAmaze/AmazeFileManager/pull/1815" }, { "type": "WEB", "url": "https://github.com/TeamAmaze/AmazeFileManager/compare/v3.4.1...v3.4.2" }, { "type": "WEB", "url": "https://play.google.com/store/apps/details?id=com.amaze.filemanager&hl=en_US&gl=US" } ], "database_specific": { "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2020-12-30T20:15:00Z" } }