PT-2022-11201 · Tencent · Wechat

Published

2022-07-26

·

Updated

2022-08-04

·

CVE-2021-40180

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WeChat versions 8.0.10
Description A mini program in the WeChat application can obtain sensitive information from a user's address book via wx.searchContacts. This issue allows unauthorized access to user data.
Recommendations For WeChat version 8.0.10, consider restricting the use of the wx.searchContacts function until a patch is available to prevent unauthorized access to sensitive information.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2021-40180

Affected Products

Wechat