The Metaclassy Byword app 2.x before 2.1 for iOS does not require confirmation of Replace file actions, which allows remote attackers to overwrite arbitrary files via the name and text parameters in a byword://replace URL.
Score: 0.0
Priority: Unclassified
Score: 0.00243
Percentile:
0.47512
CVSS v2 Score: 5.0
Severity: