{"api_version":"1","generated_at":"2026-07-23T12:13:07+00:00","cve":"CVE-2023-36621","urls":{"html":"https://cve.report/CVE-2023-36621","api":"https://cve.report/api/cve/CVE-2023-36621.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-36621","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-36621"},"summary":{"title":"CVE-2023-36621","description":"An issue was discovered in the Boomerang Parental Control application through 13.83 for Android. The child can use Safe Mode to remove all restrictions temporarily or uninstall the application without the parents noticing.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2023-11-03 04:15:00","updated_at":"2023-11-09 21:55:00"},"problem_types":["CWE-862"],"metrics":[],"references":[{"url":"https://sec-consult.com/blog/detail/the-hidden-costs-of-parental-control-apps/","name":"https://sec-consult.com/blog/detail/the-hidden-costs-of-parental-control-apps/","refsource":"MISC","tags":[],"title":"The hidden costs of parental control apps - SEC Consult","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://seclists.org/fulldisclosure/2023/Jul/12","name":"https://seclists.org/fulldisclosure/2023/Jul/12","refsource":"MISC","tags":[],"title":"Full Disclosure: SEC Consult SA-20230628-0 :: Stored XSS & Privilege Escalation in Boomerang Parental Control App","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://useboomerang.com/","name":"https://useboomerang.com/","refsource":"MISC","tags":[],"title":"Boomerang Parental Control - Taking the battle out of screen time","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-36621","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-36621","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"36621","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nationaledtech","cpe5":"boomerang","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2023-36621","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in the Boomerang Parental Control application through 13.83 for Android. The child can use Safe Mode to remove all restrictions temporarily or uninstall the application without the parents noticing."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://sec-consult.com/blog/detail/the-hidden-costs-of-parental-control-apps/","refsource":"MISC","name":"https://sec-consult.com/blog/detail/the-hidden-costs-of-parental-control-apps/"},{"url":"https://useboomerang.com/","refsource":"MISC","name":"https://useboomerang.com/"},{"refsource":"MISC","name":"https://seclists.org/fulldisclosure/2023/Jul/12","url":"https://seclists.org/fulldisclosure/2023/Jul/12"}]}},"nvd":{"publishedDate":"2023-11-03 04:15:00","lastModifiedDate":"2023-11-09 21:55:00","problem_types":["CWE-862"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.2}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nationaledtech:boomerang:*:*:*:*:*:android:*:*","versionEndExcluding":"13.83","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}