Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3x9p-x3q5-7j89

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Huawei AppGallery versions before 8.0.4.301 has an arbitrary Javascript running vulnerability. An attacker may set up a malicious network environment and trick user into accessing a malicious web page to bypass the whitelist mechanism, which make the malicious Javascript loaded and run in the smart phone.

Huawei AppGallery versions before 8.0.4.301 has an arbitrary Javascript running vulnerability. An attacker may set up a malicious network environment and trick user into accessing a malicious web page to bypass the whitelist mechanism, which make the malicious Javascript loaded and run in the smart phone.

EPSS

Процентиль: 22%
0.00074
Низкий

8.8 High

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 8.8
nvd
почти 8 лет назад

Huawei AppGallery versions before 8.0.4.301 has an arbitrary Javascript running vulnerability. An attacker may set up a malicious network environment and trick user into accessing a malicious web page to bypass the whitelist mechanism, which make the malicious Javascript loaded and run in the smart phone.

EPSS

Процентиль: 22%
0.00074
Низкий

8.8 High

CVSS3

Дефекты

CWE-345