A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview's whitelist checking function allowing javascript protocol to be loaded and can be exploited by attackers to steal Xiaomi cloud service account's cookies.
History

Fri, 27 Sep 2024 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Xiaomi

Published: 2023-08-02T00:00:00

Updated: 2024-09-27T21:58:10.819Z

Reserved: 2023-02-22T00:00:00

Link: CVE-2023-26316

cve-icon Vulnrichment

Updated: 2024-08-02T11:46:24.361Z

cve-icon NVD

Status : Analyzed

Published: 2023-08-02T14:15:10.343

Modified: 2023-08-07T18:01:47.890

Link: CVE-2023-26316

cve-icon Redhat

No data.