5.5
CVSSv3

CVE-2019-2196

Published: 13/11/2019 Updated: 15/11/2019
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 436
Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

In Download Provider, there is possible SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-135269143

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google android 8.0

google android 8.1

google android 9.0

google android 10.0

Github Repositories

PoC Exploiting SQL Injection in Android's Download Provider in Sort Parameter (CVE-2019-2196)

AOSP-DownloadProviderDbDumperSQLiLimit PoC Exploiting SQL Injection in Android's Download Provider in Sort Parameter (CVE-2019-2196) Security Advisory Android (AOSP) Download Provider SQL Injection in Query Sort Parameter (CVE-2019-2196) Demo