CVE Database
/

CVE-2023-26316

Back to search

CVE-2023-26316

Published: Aug 2, 2023

Modified: Sep 27, 2024

PUBLISHED

Description

A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview's whitelist checking function allowing javascript protocol to be loaded and can be exploited by attackers to steal Xiaomi cloud service account's cookies.

VendorProductVersions

n/a

Xiaomi cloud service Application

affected
Xiaomi cloud service Application < 1.12.0.0.25

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now