CVE-2023-46918: Fedirtsapana Simple HTTP Server Plus
Medium severity, CVSS 4.6. EPSS: 0.3% chance of exploitation in the next 30 days.
Phlox com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus has an Android manifest file that contains an entry with the android:allowBackup attribute set to true. This could be leveraged by an attacker with physical access to the device.
Affected products
- Fedirtsapana Simple HTTP Server Plus: version 1.8.1-plus only
Published 2023-12-27. Last modified 2026-06-17.