436
VMScore

CVE-2019-2198

Published: 13/11/2019 Updated: 15/11/2019
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 436
Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

In Download Provider, there is a possible SQL injection vulnerability. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-135270103

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google android 8.0

google android 8.1

google android 9.0

google android 10.0

Github Repositories

PoC Exploiting SQL Injection in Android's Download Provider in Selection Parameter (CVE-2019-2198)

AOSP-DownloadProviderDbDumperSQLiWhere PoC Exploiting SQL Injection in Android's Download Provider in Selection Parameter (CVE-2019-2198) Security Advisory Android (AOSP) Download Provider SQL Injection in Query Selection Parameter (CVE-2019-2198) Demo