GramAddict through 1.2.3 allows remote attackers to execute arbitrary code because of use of UIAutomator2 and ATX-Agent. The attacker must be able to reach TCP port 7912, e.g., by being on the same Wi-Fi network.
References
Link | Resource |
---|---|
https://github.com/GramAddict/bot/issues/134 | Exploit Third Party Advisory |
https://github.com/GramAddict/bot/issues/134 | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 05:29
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/GramAddict/bot/issues/134 - Exploit, Third Party Advisory |
Information
Published : 2021-02-17 22:15
Updated : 2024-11-21 05:29
NVD link : CVE-2020-36245
Mitre link : CVE-2020-36245
CVE.ORG link : CVE-2020-36245
JSON object : View
Products Affected
gramaddict
- gramaddict
CWE
CWE-306
Missing Authentication for Critical Function