Описание
Some js interfaces in the Xiaomi community were exposed, causing sensitive functions to be maliciously called on Xiaomi community app Affected Version <3.0.210809
Ссылки
- Broken LinkVendor Advisory
- Broken LinkVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.0.210809 (исключая)
cpe:2.3:a:mi:xiaomi:*:*:*:*:*:*:*:*
EPSS
Процентиль: 47%
0.00241
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-668
Связанные уязвимости
github
больше 3 лет назад
Some js interfaces in the Xiaomi community were exposed, causing sensitive functions to be maliciously called on Xiaomi community app Affected Version <3.0.210809
EPSS
Процентиль: 47%
0.00241
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-668