CVE-2023-26324

A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mi:getapps:*:*:*:*:*:*:*:*

History

12 Sep 2024, 17:27

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 9.8
First Time Mi
Mi getapps
CPE cpe:2.3:a:mi:getapps:*:*:*:*:*:*:*:*
References () https://https://trust.mi.com/misrc/bulletins/advisory?cveId=544 - () https://https://trust.mi.com/misrc/bulletins/advisory?cveId=544 - Broken Link
CWE NVD-CWE-noinfo

28 Aug 2024, 14:35

Type Values Removed Values Added
CWE CWE-94

28 Aug 2024, 12:57

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de ejecución de código en el producto de aplicación XiaomiGetApps. Esta vulnerabilidad se debe a que se omite la lógica de verificación y un atacante puede aprovechar esta vulnerabilidad para ejecutar código malicioso.

28 Aug 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-28 08:15

Updated : 2024-09-12 17:27


NVD link : CVE-2023-26324

Mitre link : CVE-2023-26324

CVE.ORG link : CVE-2023-26324


JSON object : View

Products Affected

mi

  • getapps
CWE
NVD-CWE-noinfo CWE-94

Improper Control of Generation of Code ('Code Injection')