VYPR
Medium severity5.5NVD Advisory· Published Nov 6, 2020· Updated Jun 17, 2026

CVE-2020-5667

CVE-2020-5667

Description

Studyplus App for Android v6.3.7 and earlier and Studyplus App for iOS v8.29.0 and earlier use a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtained by analyzing data in the app.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:wantedlyinc:studyplus:*:*:*:*:*:android:*:*+ 1 more
    • cpe:2.3:a:wantedlyinc:studyplus:*:*:*:*:*:android:*:*range: <=6.3.7
    • cpe:2.3:a:wantedlyinc:studyplus:*:*:*:*:*:iphone_os:*:*range: <=8.29.0
  • Range: <=6.3.7 for Android, <=8.29.0 for iOS
  • Studyplus Inc./Studyplus Appv5
    Range: for Android v6.3.7 and earlier, and for iOS v8.29.0 and earlier

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.