PT-2018-18332 · Huawei · Gallery App

Published

2018-04-24

·

Updated

2019-10-03

·

CVE-2018-7932

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Huawei AppGallery versions prior to 8.0.4.301
Description: The issue allows an attacker to bypass the whitelist mechanism by setting up a malicious network environment and tricking a user into accessing a malicious web page, which can lead to the execution of arbitrary Javascript. This can result in malicious Javascript being loaded and run on a smartphone.
Recommendations: For versions prior to 8.0.4.301, update to version 8.0.4.301 or later to resolve the issue. As a temporary workaround, consider restricting access to untrusted web pages to minimize the risk of exploitation.

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-7932
ZDI-18-875

Affected Products

Gallery App