Xiaomi Pro 13 Cross-Site Scripting Remote Code Execution Vulnerability
CVE-2024-4405
8.8HIGH
What is CVE-2024-4405?
The vulnerability identified in Xiaomi Pro 13 smartphones involves a Cross-Site Scripting (XSS) flaw within the manual-upgrade.html file. This security issue arises when the manualUpgradeInfo parameter is processed, failing to adequately sanitize inputs provided by users. As a result, remote attackers can exploit this vulnerability by persuading users to visit malicious web pages or open harmful files, leading to the execution of arbitrary code under the context of the user. The flaw emphasizes the need for stringent input validation to prevent unauthorized code execution and protect user data from potential threats.
Affected Version(s)
Pro 13 14.0.5.0