NA

CVE-2023-26316

Published: 02/08/2023 Updated: 07/08/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview's whitelist checking function allowing javascript protocol to be loaded and can be exploited by malicious users to steal Xiaomi cloud service account's cookies.

Vulnerable Product Search on Vulmon Subscribe to Product

mi xiaomi cloud