CVE-2026-30279

An arbitrary file overwrite vulnerability in Squareapps LLC My Location Travel Timeline v11.80 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:squareapps:my_location:11.80:*:*:*:*:android:*:*

History

03 Apr 2026, 18:32

Type Values Removed Values Added
First Time Squareapps my Location
Squareapps
CPE cpe:2.3:a:squareapps:my_location:11.80:*:*:*:*:android:*:*
References () http://my.com - () http://my.com - Broken Link
References () https://github.com/Secsys-FDU/AF_CVEs/issues/28 - () https://github.com/Secsys-FDU/AF_CVEs/issues/28 - Third Party Advisory
References () https://lightapp3.firebaseapp.com/ - () https://lightapp3.firebaseapp.com/ - Product
References () https://secsys.fudan.edu.cn/ - () https://secsys.fudan.edu.cn/ - Not Applicable

02 Apr 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.4
CWE CWE-22

31 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-31 18:16

Updated : 2026-04-03 18:32


NVD link : CVE-2026-30279

Mitre link : CVE-2026-30279

CVE.ORG link : CVE-2026-30279


JSON object : View

Products Affected

squareapps

  • my_location
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')