CVE-2021-40180

In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.searchContacts.
References
Link Resource
https://arxiv.org/pdf/2205.15202.pdf Mitigation Technical Description Third Party Advisory
https://github.com/BESTICSP/Vulnerabilities-Related-to-Mini-Programs-Permissions/blob/main/WX%20applet%20contact%20permission%20vulnerability%20report.pdf Exploit Third Party Advisory
https://pan.baidu.com/s/116sAQvs1CEzCeIfpI1NZvA Exploit Permissions Required Third Party Advisory
https://pan.baidu.com/s/1RqMrZBruZZ4OHdnXUN5xDw Exploit Permissions Required Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:tencent:wechat:8.0.10:*:*:*:*:android:*:*
cpe:2.3:a:tencent:wechat:8.0.10:*:*:*:*:iphone_os:*:*

History

No history.

Information

Published : 2022-07-26 23:15

Updated : 2024-02-28 19:29


NVD link : CVE-2021-40180

Mitre link : CVE-2021-40180

CVE.ORG link : CVE-2021-40180


JSON object : View

Products Affected

tencent

  • wechat
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor