What the vulnerability does
01Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Retrieve Embedded Sensitive Data.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3.
Explanation of Vulnerability in Simple Terms
02Summary
Stacks Mobile App Builder versions 5.2.3 and earlier expose sensitive information to unauthenticated attackers over the network. An attacker can read confidential data without needing valid credentials or user interaction. The vulnerability affects all versions from release through 5.2.3. Update to a version newer than 5.2.3 to remediate.
What an attacker can do
03Attacker Capabilities
Read sensitive information from the app builder without authentication.
Potential impact on your site
04Site Impact
Confidential data stored in or processed by the app builder is exposed to anyone on the network.
Conditions required to exploit
05Prerequisites
Network access to the affected Stacks Mobile App Builder instance; no authentication required.
Key dates
06Disclosure timeline
November 4, 2024
CVE published
May 11, 2026
Record updated