CVE-2018-14066
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
15/07/2018
Last modified:
21/09/2018
Description
The content://wappush content provider in com.android.provider.telephony, as found in some custom ROMs for Android phones, allows SQL injection. One consequence is that an application without the READ_SMS permission can read SMS messages. This affects Infinix X571 phones, as well as various Lenovo phones (such as the A7020) that have since been fixed by Lenovo.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:google:android:7.0:*:*:*:*:*:*:* | ||
| cpe:2.3:h:infinixmobility:infinix_x571:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lenovo:lenovo_a7020:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



