CVE-2019-14759 | xxxCVE-2019-14759 – xxx
菜单

CVE-2019-14759

九月 13, 2020 - 未分类

  1. CVE-Search
  2. CVE-2019-14759
ID CVE-2019-14759
SummaryAn issue was discovered in KaiOS 1.0, 2.5, and 2.5.1. The pre-installed Radio application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the Radio application. At a bare minimum, this allows an attacker to take control over the Radio application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.
References
Vulnerable Configurations

    CVSS
    Base: 5.0
    Impact:
    Exploitability:
    Access
    VectorComplexityAuthentication
    Impact
    ConfidentialityIntegrityAvailability
    Last major update14-09-2020 – 20:17
    Published14-09-2020 – 20:15
    Last modified14-09-2020 – 20:17

    Notice: Undefined variable: canUpdate in /var/www/html/wordpress/wp-content/plugins/wp-autopost-pro/wp-autopost-function.php on line 51