Описание
information leakage vulnerability exists in the Xiaomi SmartHome APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which can be exploited by attackers to leak sensitive information.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.4.701 (включая)
cpe:2.3:a:mi:smarthome:*:*:*:*:*:*:*:*
EPSS
Процентиль: 51%
0.00703
Низкий
7.5 High
CVSS3
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 7.5
github
около 4 лет назад
information leakage vulnerability exists in the Xiaomi SmartHome APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which can be exploited by attackers to leak sensitive information.
EPSS
Процентиль: 51%
0.00703
Низкий
7.5 High
CVSS3
Дефекты
NVD-CWE-noinfo