5.3
CVE-2018-20523
- EPSS 6.19%
- Veröffentlicht 07.06.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:39
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can read the user's cleartext browser history via an app.provider.query content://com.android.browser.searchhistory/searchhistory request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mi ≫ Stock Browser Version10.2.4g
Mi ≫ Redmi 7 Firmware Version-
Mi ≫ Redmi Note 7 Firmware Version-
Mi ≫ Redmi Note 6 Pro Firmware Version-
Mi ≫ Redmi 6 Firmware Version-
Mi ≫ Redmi 6a Firmware Version-
Mi ≫ Redmi S2 Firmware Version-
Mi ≫ Redmi Note 5 Pro Firmware Version-
Mi ≫ Redmi K20 Pro Firmware Version-
Mi ≫ Redmi K20 Firmware Version-
Mi ≫ Redmi 7a Firmware Version-
Mi ≫ Redmi Go Firmware Version-
Mi ≫ Redmi Note 5 Firmware Version-
Mi ≫ Redmi Y3 Firmware Version-
Mi ≫ Redmi Note 7s Firmware Version-
Mi ≫ Redmi S2 Firmware Version-
Mi ≫ Redmi 4a Firmware Version-
Mi ≫ Redmi Note 4 Firmware Version-
Mi ≫ Redmi 5 Plus Firmware Version-
Mi ≫ Redmi Note 5a Prime Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 6.19% | 0.905 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.