Vulnerability updated a month ago (2024-11-29T14:13:14.652Z)
Download STIX
Preview STIX
CVE-2023-28153 is a vulnerability in the software of Kiddoware's "Kids Place" application. This vulnerability allows a child user to remove all restrictions temporarily without the parent's notice. This flaw arises due to weak password security practices, where the passwords are stored as MD5 hashes. Additionally, the vulnerability can be exploited by rebooting into Android Safe Mode if Android settings are blocked.
The proof of concept for this vulnerability involves sending an HTTP request to change the password and receiving an MD5 hash of the password as a response. Once a child user gains access to the account, they can disable app restrictions without the parent's knowledge by following specific steps, including rebooting into Android Safe Mode.
This vulnerability poses a significant risk to parents who rely on "Kids Place" to restrict their children's device usage. If exploited, it could lead to unintended exposure to inappropriate content, online predators, and addiction to technology. To mitigate this vulnerability, Kiddoware should update its password storage mechanism and implement stronger password policies, among other security measures.
Description last updated: 2023-06-13T16:19:43.024Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the CVE-2023-28153 Vulnerability was read from the documents corpus below. This display is limited to 20 results, create a free account to see more