PT-2018-18332 · Huawei · Gallery App
Published
2018-04-24
·
Updated
2019-10-03
·
CVE-2018-7932
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Huawei AppGallery versions prior to 8.0.4.301
Description:
The issue allows an attacker to bypass the whitelist mechanism by setting up a malicious network environment and tricking a user into accessing a malicious web page, which can lead to the execution of arbitrary Javascript. This can result in malicious Javascript being loaded and run on a smartphone.
Recommendations:
For versions prior to 8.0.4.301, update to version 8.0.4.301 or later to resolve the issue. As a temporary workaround, consider restricting access to untrusted web pages to minimize the risk of exploitation.
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gallery App