Input Validation Vulnerability in Huawei iReader App
CVE-2017-15308

8.8HIGH

Key Information:

Vendor
McAfee
Status
Vendor
CVE Published:
22 December 2017

Summary

The Huawei iReader app prior to version 8.0.2.301 contains an input validation vulnerability that stems from inadequate validation of URLs for loading network data. An attacker who exploits this vulnerability can manipulate app access, enabling the loading and execution of malicious web pages crafted by the attacker. Users of the affected app versions are at risk of exposing their devices to harmful content, making it essential for them to update to the latest version for optimal security.

Affected Version(s)

iReader before 8.0.2.301

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.