CVE-2023-46918: Fedirtsapana Simple HTTP Server Plus

Medium severity, CVSS 4.6. EPSS: 0.3% chance of exploitation in the next 30 days.

Phlox com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus has an Android manifest file that contains an entry with the android:allowBackup attribute set to true. This could be leveraged by an attacker with physical access to the device.

Affected products

  • Fedirtsapana Simple HTTP Server Plus: version 1.8.1-plus only

Published 2023-12-27. Last modified 2026-06-17.