CVE-2025-5154

A vulnerability, which was classified as problematic, was found in PhonePe App 25.03.21.0 on Android. Affected is an unknown function of the file /data/data/com.phonepe.app/databases/ of the component SQLite Database. The manipulation leads to cleartext storage in a file or on disk. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phonepe:phonepe:25.03.21.0:*:*:*:*:android:*:*

History

03 Jun 2025, 13:53

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-25 19:15

Updated : 2025-06-03 13:53


NVD link : CVE-2025-5154

Mitre link : CVE-2025-5154

CVE.ORG link : CVE-2025-5154


JSON object : View

Products Affected

phonepe

  • phonepe
CWE
CWE-312

Cleartext Storage of Sensitive Information

CWE-313

Cleartext Storage in a File or on Disk