Android Gmail Attachment Download Directory Traversal
Posted by deepcore on November 29, 2017 – 11:03 pm
There is a directory traversal issue in attachment downloads in Gmail. For non-gmail accounts, there is no path sanitization on the attachment filename in the email, so when attachments are downloaded, a file with any name and any contents can be written to anywhere on the filesystem that the Gmail app can access.
Post a reply
You must be logged in to post a comment.