Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hqq7-9p4f-x9pj

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by allowing unauthenticated access to read data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would need to execute arbitrary code on the Android device.

Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by allowing unauthenticated access to read data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would need to execute arbitrary code on the Android device.

EPSS

Процентиль: 77%
0.01036
Низкий

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 6.5
nvd
около 5 лет назад

Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by allowing unauthenticated access to read data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would need to execute arbitrary code on the Android device.

EPSS

Процентиль: 77%
0.01036
Низкий

Дефекты

CWE-94