MEDIUM
An issue was discovered in KaiOS 2.5 and 2.5.1
Published Sep 14, 2020
6.1
MEDIUMCVSS 3.1
EPSS 0.83%
Description
An issue was discovered in KaiOS 2.5 and 2.5.1. The pre-installed Contacts application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a vCard file to the victim that will inject HTML into the Contacts application (assuming the victim chooses to import the file). At a bare minimum, this allows an attacker to take control over the Contacts application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-5896 Advisory
- https://research.nccgroup.com/2020/08/21/technical-advisory-multiple-html-injection-vulnerabilities-in-kaios-pre-installed-mobile-applications/ x_refsource_MISCThird Party Advisory
- https://www.nccgroup.trust/us/our-research/ x_refsource_MISCThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-5896 | Advisory | |
| https://research.nccgroup.com/2020/08/21/technical-advisory-multiple-html-injection-vulnerabilities-in-kaios-pre-installed-mobile-applications/ | x_refsource_MISCThird Party Advisory | |
| https://www.nccgroup.trust/us/our-research/ | x_refsource_MISCThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 14, 2020
Updated Aug 5, 2024
Reserved Aug 7, 2019
Link CVE-2019-14757
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-5896 Assigner mitre
Published Sep 14, 2020
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2019-5896