Xiaomi Pro 13 GetApps integral-dialog-page Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Xiaomi Pro 13 smartphones. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the integral-dialog-page.html file. When parsing the integralInfo parameter, the process does not properly sanitize user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-22332.
The vulnerability is located in the integral-dialog-page.html file that is part of the GetApps application. When processing the integralInfo parameter, the application does not properly sanitize user-supplied data, allowing arbitrary script injection (XSS). An attacker can trick a victim into visiting a malicious website or opening a malicious file, after which the injected code is executed in the context of the current user.
An attacker can execute arbitrary code in the context of a logged-in device user, which may lead to violations of data and system function confidentiality, integrity, and availability.
Apply patches available from the manufacturer according to the references. It is recommended to monitor software updates for Xiaomi 13 Pro firmware and avoid opening files or visiting websites from untrusted sources.
Xiaomi 13 Pro and Xiaomi 13 Pro Firmware (versions indicated in manufacturer and Zero Day Initiative references)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HMi Xiaomi 13 Pro
HWMiall versionsMi Xiaomi 13 Pro Firmware
OSMi14.0.5.0
Related vulnerabilities
XSS umożliwiający RCE w Xiaomi 13 Pro — plik manual-upgrade.html
Krytyczna podatność w urządzeniach Xiaomi Mi (CVE-2020-14131)
Błąd logiczny w produkcie Xiaomi — nieprawidłowa weryfikacja tożsamości
Command injection w routerze Xiaomi AX3600 — zdalne wykonanie kodu
Command injection w interfejsie addMeshNode routera Xiaomi AX3600