CVE-2023-26322

A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:mi:getapps:*:*:*:*:*:*:*:*

History

12 Sep 2024, 17:27

Type Values Removed Values Added
CWE NVD-CWE-noinfo

12 Sep 2024, 17:18

Type Values Removed Values Added
References () https://trust.mi.com/misrc/bulletins/advisory?cveId=542 - () https://trust.mi.com/misrc/bulletins/advisory?cveId=542 - Vendor Advisory
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 9.8
First Time Mi
Mi getapps
CPE cpe:2.3:a:mi:getapps:*:*:*:*:*:*:*:*

28 Aug 2024, 14:35

Type Values Removed Values Added
CWE CWE-94

28 Aug 2024, 12:57

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de ejecución de código en el producto de aplicación XiaomiGetApps. Esta vulnerabilidad se debe a que se omite la lógica de verificación y un atacante puede aprovechar esta vulnerabilidad para ejecutar código malicioso.

28 Aug 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-28 08:15

Updated : 2024-09-12 17:27


NVD link : CVE-2023-26322

Mitre link : CVE-2023-26322

CVE.ORG link : CVE-2023-26322


JSON object : View

Products Affected

mi

  • getapps
CWE
NVD-CWE-noinfo CWE-94

Improper Control of Generation of Code ('Code Injection')