HIGH🇵🇱 Wersja polska

CVE-2019-13321

CVSS 8.0v3.1pub. 2020-02-10upd. 2024-11-21

This vulnerability allows network adjacent attackers to execute arbitrary code on affected installations of Xiaomi Browser Prior to 10.4.0. User interaction is required to exploit this vulnerability in that the target must connect to a malicious access point. The specific flaw exists within the handling of HTTP responses to the Captive Portal. A crafted HTML response can cause the Captive Portal to to open a browser to a specified location without user interaction. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-7467.

CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Mi Browser

    APP
    Mi
    < 10.4.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2020-14116HIGH7.5same product

An intent redirection vulnerability in the Mi Browser product. This vulnerability is caused by the Mi Browser ...

CVE-2019-13322HIGH8.8same product

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Bro...

CVE-2019-10875MEDIUM6.5same product

A URL spoofing vulnerability was found in all international versions of Xiaomi Mi browser 10.5.6-g (aka the MI...

CVE-2024-4405CRITICAL9.6PL ✓same vendor

XSS umożliwiający RCE w Xiaomi 13 Pro — plik manual-upgrade.html

CVE-2024-4406CRITICAL9.6PL ✓same vendor

XSS umożliwiający RCE w aplikacji GetApps na Xiaomi 13 Pro