---
id: CVE-2026-30279
title: >-
  An arbitrary file overwrite vulnerability in Squareapps LLC My Location Travel
  Timeline v11.80 allows attackers to overwrite critical internal files via the
  file import process, leading to arbitrary code execution or information
  exposure.
summary: >-
  An arbitrary file overwrite vulnerability in Squareapps LLC My Location Travel
  Timeline v11.80 allows attackers to overwrite critical internal files via the
  file import process, leading to arbitrary code execution or information
  exposure.
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
vendor: squareapps
product: my_location
affected:
  - my_location = 11.80
published: '2026-03-31'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-30279'
references:
  - url: 'https://github.com/Secsys-FDU/AF_CVEs/issues/28'
    label: cve@mitre.org
  - url: 'https://lightapp3.firebaseapp.com/'
    label: cve@mitre.org
  - url: 'https://secsys.fudan.edu.cn/'
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00215
epssPercentile: 0.10641
ingestedAt: '2026-07-24T20:38:03.079Z'
---

## Overview

An arbitrary file overwrite vulnerability in Squareapps LLC My Location Travel Timeline v11.80 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

## Affected

- `my_location = 11.80`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
