CVE-2019-14756
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
14/09/2020
Last modified:
17/09/2020
Description
An issue was discovered in KaiOS 1.0, 2.5, and 2.5.12.5. The pre-installed Email application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a specially crafted email to the victim that will inject HTML into the email application's UI as soon as the email is opened. At a bare minimum, this allows an attacker to take control over the Email application's UI (e.g., display a malicious prompt to the user asking them to re-enter their email credentials) and also allows an attacker to abuse any of the privileges available to the mobile application.
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:kaiostech:kaios:1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:kaiostech:kaios:2.5:*:*:*:*:*:*:* | ||
| cpe:2.3:o:kaiostech:kaios:2.5.12.5:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



