CVE-2019-14758 | xxxCVE-2019-14758 – xxx
菜单

CVE-2019-14758

九月 13, 2020 - 未分类

  1. CVE-Search
  2. CVE-2019-14758
ID CVE-2019-14758
SummaryAn issue was discovered in KaiOS 2.5 and 2.5.1. The pre-installed File Manager application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a file via email to the victim that will inject HTML into the File Manager application (assuming the victim chooses to download the email attachment). At a bare minimum, this allows an attacker to take control over the File Manager application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.
References
Vulnerable Configurations

    CVSS
    Base: 5.0
    Impact:
    Exploitability:
    Access
    VectorComplexityAuthentication
    Impact
    ConfidentialityIntegrityAvailability
    Last major update14-09-2020 – 20:17
    Published14-09-2020 – 20:15
    Last modified14-09-2020 – 20:17

    Notice: Undefined variable: canUpdate in /var/www/html/wordpress/wp-content/plugins/wp-autopost-pro/wp-autopost-function.php on line 51