Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wm5r-jw2j-wfcp

Опубликовано: 28 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.

A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.

EPSS

Процентиль: 33%
0.0013
Низкий

8.8 High

CVSS3

Дефекты

CWE-287
CWE-94

Связанные уязвимости

CVSS3: 8.8
nvd
больше 1 года назад

The Xiaomi Security Center expresses heartfelt thanks to Ken Gannon and Ilyes Beghdadi of NCC Group working with Trend Micro Zero Day Initiative! At the same time, we also welcome more outstanding and professional security experts and security teams to join the Mi Security Center (MiSRC) to jointly ensure the safe access of millions of Xiaomi users worldwide Life.

EPSS

Процентиль: 33%
0.0013
Низкий

8.8 High

CVSS3

Дефекты

CWE-287
CWE-94