CVE-2018-7932

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
24/04/2018
Last modified:
03/10/2019

Description

Huawei AppGallery versions before 8.0.4.301 has an arbitrary Javascript running vulnerability. An attacker may set up a malicious network environment and trick user into accessing a malicious web page to bypass the whitelist mechanism, which make the malicious Javascript loaded and run in the smart phone.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:huawei:appgallery:*:*:*:*:*:*:*:* 8.0.4.301 (excluding)