CVE-2018-20523

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
07/06/2019
Last modified:
19/04/2022

Description

Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can read the user's cleartext browser history via an app.provider.query content://com.android.browser.searchhistory/searchhistory request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mi:stock_browser:10.2.4g:*:*:*:*:*:*:*
cpe:2.3:o:mi:redmi_7_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:mi:redmi_7:-:*:*:*:*:*:*:*
cpe:2.3:o:mi:redmi_note_7_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:mi:redmi_note_7:-:*:*:*:*:*:*:*
cpe:2.3:o:mi:redmi_note_6_pro_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:mi:redmi_note_6_pro:-:*:*:*:*:*:*:*
cpe:2.3:o:mi:redmi_6_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:mi:redmi_6:-:*:*:*:*:*:*:*
cpe:2.3:o:mi:redmi_6a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:mi:redmi_6a:-:*:*:*:*:*:*:*
cpe:2.3:o:mi:redmi_s2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:mi:redmi_s2:-:*:*:*:*:*:*:*
cpe:2.3:o:mi:redmi_note_5_pro_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:mi:redmi_note_5_pro:-:*:*:*:*:*:*:*