PT-2022-8553 · Xiaomi · Mi App Store

Published

2022-04-21

·

Updated

2022-05-03

·

CVE-2020-14118

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mi App Store (affected versions not specified)
Description The issue is caused by the Mi App Store not verifying the validity of incoming data, which can lead to the app store automatically downloading and installing apps. This is due to an intent redirection vulnerability in the Mi App Store product.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-14118

Affected Products

Mi App Store