Description
A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview's whitelist checking function allowing javascript protocol to be loaded and can be exploited by attackers to steal Xiaomi cloud service account's cookies.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-30137 | A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview's whitelist checking function allowing javascript protocol to be loaded and can be exploited by attackers to steal Xiaomi cloud service account's cookies. |
References
History
Fri, 27 Sep 2024 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Xiaomi
Published:
Updated: 2024-09-27T21:58:10.819Z
Reserved: 2023-02-22T00:00:00.000Z
Link: CVE-2023-26316
Updated: 2024-08-02T11:46:24.361Z
Status : Modified
Published: 2023-08-02T14:15:10.343
Modified: 2024-11-21T07:51:06.657
Link: CVE-2023-26316
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD