CVE-2023-40040

An issue was discovered in the MyCrops HiGrade "THC Testing & Cannabi" application 1.0.337 for Android. A remote attacker can start the camera feed via the com.cordovaplugincamerapreview.CameraActivity component in some situations. NOTE: this is only exploitable on Android versions that lack runtime permission checks, and of those only Android SDK 5.1.1 API 22 is consistent with the manifest. Thus, this applies only to Android Lollipop, affecting less than five percent of Android devices as of 2023.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:mycrops:higrade:1.0.337:*:*:*:*:*:*:*
cpe:2.3:o:google:android:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:18

Type Values Removed Values Added
References () https://github.com/actuator/cve/blob/main/CVE-2023-40040 - Third Party Advisory () https://github.com/actuator/cve/blob/main/CVE-2023-40040 - Third Party Advisory

13 Sep 2023, 14:31

Type Values Removed Values Added
CWE CWE-862
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CPE cpe:2.3:a:mycrops:higrade:1.0.337:*:*:*:*:*:*:*
cpe:2.3:o:google:android:*:*:*:*:*:*:*:*
References (MISC) https://github.com/actuator/cve/blob/main/CVE-2023-40040 - (MISC) https://github.com/actuator/cve/blob/main/CVE-2023-40040 - Third Party Advisory
First Time Google android
Mycrops higrade
Google
Mycrops

11 Sep 2023, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-11 06:15

Updated : 2024-11-21 08:18


NVD link : CVE-2023-40040

Mitre link : CVE-2023-40040

CVE.ORG link : CVE-2023-40040


JSON object : View

Products Affected

mycrops

  • higrade

google

  • android
CWE
CWE-862

Missing Authorization