Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2pgp-5w4w-9255

Опубликовано: 11 сент. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

Govee Home app has unprotected access to WebView component which can be opened by any app on the device. By sending an URL to a specially crafted site, the attacker can execute JavaScript in context of WebView or steal sensitive user data by displaying phishing content.

Govee Home app has unprotected access to WebView component which can be opened by any app on the device. By sending an URL to a specially crafted site, the attacker can execute JavaScript in context of WebView or steal sensitive user data by displaying phishing content.

EPSS

Процентиль: 22%
0.00071
Низкий

8.2 High

CVSS3

Дефекты

CWE-749

Связанные уязвимости

CVSS3: 8.2
nvd
больше 2 лет назад

Govee Home app has unprotected access to WebView component which can be opened by any app on the device. By sending an URL to a specially crafted site, the attacker can execute JavaScript in context of WebView or steal sensitive user data by displaying phishing content.

EPSS

Процентиль: 22%
0.00071
Низкий

8.2 High

CVSS3

Дефекты

CWE-749