{"id": "CVE-2018-20523", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 5.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 5.3, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "LOW"}, "impactScore": 1.4, "exploitabilityScore": 3.9}]}, "published": "2019-06-07T16:29:00.440", "references": [{"url": "http://packetstormsecurity.com/files/163796/Xiaomi-10.2.4.g-Information-Disclosure.html", "tags": ["Exploit", "Third Party Advisory", "VDB Entry"], "source": "cve@mitre.org"}, {"url": "https://sec.xiaomi.com", "tags": ["Broken Link", "Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "https://vishwarajbhattrai.wordpress.com/2019/03/22/content-provider-injection-in-xiaomi-stock-browser", "tags": ["Exploit", "Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "http://packetstormsecurity.com/files/163796/Xiaomi-10.2.4.g-Information-Disclosure.html", "tags": ["Exploit", "Third Party Advisory", "VDB Entry"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://sec.xiaomi.com", "tags": ["Broken Link", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://vishwarajbhattrai.wordpress.com/2019/03/22/content-provider-injection-in-xiaomi-stock-browser", "tags": ["Exploit", "Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-77"}]}], "descriptions": [{"lang": "en", "value": "Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can read the user's cleartext browser history via an app.provider.query content://com.android.browser.searchhistory/searchhistory request."}, {"lang": "es", "value": "Xiaomi stock Browser versi\u00f3n 10.2.4.g en dispositivos Xiaomi Redmi Note 5 Pro y otros tel\u00e9fonos Redmi Android, permite inyecci\u00f3n en el proveedor de contenido. En otras palabras, una aplicaci\u00f3n de terceros puede leer el historial del explorador del usuario en texto sin cifrar mediante una petici\u00f3n app.provider.query content://com.android.browser.searchhistory/searchhistory."}], "lastModified": "2024-11-21T04:01:39.083", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:mi:stock_browser:10.2.4g:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A0DC836E-A962-4696-B765-9DAB9B8D2309"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mi:redmi_7_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E8288623-A43F-46F6-9B59-BBCFEC0AC565"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mi:redmi_7:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C86BB5D5-B558-454D-AA19-90BDD0DD7EC0"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mi:redmi_note_7_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5B0A059E-F85B-4881-B871-774FD04FF352"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mi:redmi_note_7:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "E63A02BC-7DB7-4B66-8FAC-CDAB57E54F48"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mi:redmi_note_6_pro_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EECA2BF3-67CD-464F-825F-C592D35371D1"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mi:redmi_note_6_pro:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "55301EB8-B8CB-4751-914E-90215167CC85"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mi:redmi_6_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C8382ABD-1001-46EF-8DF8-1A4B592AEA0A"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mi:redmi_6:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "8693971A-0952-486D-B4A7-31F28F8D2499"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mi:redmi_6a_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1B132ECA-99BD-45B9-8BC1-45D1C4157C9B"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mi:redmi_6a:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "3235BB2B-2C1C-471B-84FE-7635E576D841"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mi:redmi_s2_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3BB77822-1E9A-425D-90F5-321073D424B0"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mi:redmi_s2:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "860F1BE9-BC38-4D9D-A0C4-DD6FADB0A419"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mi:redmi_note_5_pro_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A08FAE6A-A912-47E2-B52C-2285D0004DF1"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mi:redmi_note_5_pro:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "AD6D1DED-3D08-453C-ABDC-98592FCEA554"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mi:redmi_k20_pro_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "125A8634-664D-4B27-A9CE-BACC83C26660"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mi:redmi_k20_pro:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "5B2AE104-2650-464E-B8DC-3102EB918216"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mi:redmi_k20_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "72625F6B-126A-45A9-81CA-B55CA82CF857"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mi:redmi_k20:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "9F7002DB-5EB8-428C-AEFF-4C6EE3724F74"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mi:redmi_7a_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9452287A-AAF7-4F99-A61C-1F805D1E1718"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mi:redmi_7a:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "D5835E6A-8895-4A9E-9ACC-AA9A0B910A41"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mi:redmi_go_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "42E47022-5D30-4820-BFA4-C62D79B9DC4C"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mi:redmi_go:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "AD6FE0F2-9D6B-402F-B51C-A397EE487A76"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mi:redmi_note_5_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E692DE1B-5C04-4560-9115-978DED863525"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mi:redmi_note_5:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C9D5643A-363C-4F44-898C-B2E439A0A498"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mi:redmi_y3_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F7F063F6-32F9-45D1-A71F-7B62DEBDD0DA"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mi:redmi_y3:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "31B37973-86E1-4A71-B1EE-350D49A19EF2"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mi:redmi_note_7s_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9AC0B996-7930-4812-B2D3-C2C3334EE76A"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mi:redmi_note_7s:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "4E7B4FA0-55EC-4C3C-8DC7-2C50852F2E50"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mi:redmi_s2_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3BB77822-1E9A-425D-90F5-321073D424B0"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mi:redmi_s2:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "860F1BE9-BC38-4D9D-A0C4-DD6FADB0A419"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mi:redmi_4a_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0CAC196F-B4AD-4CBA-AC87-5C9FBBD9B9BF"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mi:redmi_4a:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "60C89EAF-C0BB-4A4A-953E-66A4A7164C57"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mi:redmi_note_4_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F485578A-F35B-470B-A94C-F641BE4F3F7B"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mi:redmi_note_4:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6CA7C241-4382-4C31-A03D-3DBD86A9BE73"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mi:redmi_5_plus_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0E0F1E18-5D74-4730-ADE4-AE4E4B07B373"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mi:redmi_5_plus:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "76773FBD-9BFC-4B92-9782-138A72143A08"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mi:redmi_note_5a_prime_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8E64584F-0051-49DE-8FA8-6C06A37C3447"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mi:redmi_note_5a_prime:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "24EB39E3-DC22-43FD-8435-47958DBD6B4D"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "cve@mitre.org"}