Intel

AIKIDO-2025-10144

flutter_downloader is vulnerable to SQL Injection

SQL InjectionCVE-2023-41387 Published Mar 10, 2025

91

Critical Risk

This Affects:

DARTflutter_downloader
0.0.1 - 1.11.1
Fixed in 1.11.2
Are you affected? Scan for Free

TL;DR

Affected versions of the flutter_downloader package are vulnerable to SQL injection on iOS through version 1.11.1. This allows remote attackers to steal session tokens and overwrite arbitrary files within the app's container. Additionally, if an app enables UIFileSharingEnabled and LSSupportsOpeningDocumentsInPlace, the framework's internal database is exposed to local users. This enables local attackers to achieve the same level of access as remote attackers by modifying the internal database directly on the device.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

flutter_downloader is vulnerable to SQL Injection in versions 0.0.1 - 1.11.1.

How to fix this

Upgrade the flutter_downloader library to the patch version.