Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4pf2-5j8p-ghjv

Опубликовано: 05 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 3.9

Описание

The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database across tables, including user accounts, phone numbers, feedback content, and local debug log paths, thereby enabling the theft of local privacy data.

The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database across tables, including user accounts, phone numbers, feedback content, and local debug log paths, thereby enabling the theft of local privacy data.

EPSS

Процентиль: 3%
0.00134
Низкий

3.9 Low

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 3.9
nvd
около 1 месяца назад

The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database across tables, including user accounts, phone numbers, feedback content, and local debug log paths, thereby enabling the theft of local privacy data.

EPSS

Процентиль: 3%
0.00134
Низкий

3.9 Low

CVSS3

Дефекты

CWE-89