Описание
In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.searchContacts.
In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.searchContacts.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-40180
- https://arxiv.org/pdf/2205.15202.pdf
- https://github.com/BESTICSP/Vulnerabilities-Related-to-Mini-Programs-Permissions/blob/main/WX%20applet%20contact%20permission%20vulnerability%20report.pdf
- https://pan.baidu.com/s/116sAQvs1CEzCeIfpI1NZvA
- https://pan.baidu.com/s/1RqMrZBruZZ4OHdnXUN5xDw
Связанные уязвимости
CVSS3: 7.5
nvd
больше 3 лет назад
In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.searchContacts.