CRITICAL🇵🇱 Wersja polska

CVE-2024-4406

CVSS 9.6v3.1pub. 2024-05-02upd. 2025-08-13

Xiaomi Pro 13 GetApps integral-dialog-page Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Xiaomi Pro 13 smartphones. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the integral-dialog-page.html file. When parsing the integralInfo parameter, the process does not properly sanitize user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-22332.

🤖 AI Analysis
How it works

The vulnerability is located in the integral-dialog-page.html file that is part of the GetApps application. When processing the integralInfo parameter, the application does not properly sanitize user-supplied data, allowing arbitrary script injection (XSS). An attacker can trick a victim into visiting a malicious website or opening a malicious file, after which the injected code is executed in the context of the current user.

Impact

An attacker can execute arbitrary code in the context of a logged-in device user, which may lead to violations of data and system function confidentiality, integrity, and availability.

Mitigation & patch

Apply patches available from the manufacturer according to the references. It is recommended to monitor software updates for Xiaomi 13 Pro firmware and avoid opening files or visiting websites from untrusted sources.

Who is affected

Xiaomi 13 Pro and Xiaomi 13 Pro Firmware (versions indicated in manufacturer and Zero Day Initiative references)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Mi Xiaomi 13 Pro

    HW
    Mi
    all versions
  • Mi Xiaomi 13 Pro Firmware

    OS
    Mi
    14.0.5.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEXSS
CWE
References

Related vulnerabilities

CVE-2024-4405CRITICAL9.6PL ✓same product

XSS umożliwiający RCE w Xiaomi 13 Pro — plik manual-upgrade.html

CVE-2020-14131CRITICAL9.8PL ✓same vendor

Krytyczna podatność w urządzeniach Xiaomi Mi (CVE-2020-14131)

CVE-2020-14129CRITICAL9.8PL ✓same vendor

Błąd logiczny w produkcie Xiaomi — nieprawidłowa weryfikacja tożsamości

CVE-2020-14115CRITICAL9.8PL ✓same vendor

Command injection w routerze Xiaomi AX3600 — zdalne wykonanie kodu

CVE-2020-14119CRITICAL9.8PL ✓same vendor

Command injection w interfejsie addMeshNode routera Xiaomi AX3600