Lucene search

K
prionPRIOn knowledge basePRION:CVE-2019-14756
HistorySep 14, 2020 - 7:15 p.m.

Input validation

2020-09-1419:15:00
PRIOn knowledge base
www.prio-n.com
3

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.3%

An issue was discovered in KaiOS 1.0, 2.5, and 2.5.12.5. The pre-installed Email application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a specially crafted email to the victim that will inject HTML into the email application’s UI as soon as the email is opened. At a bare minimum, this allows an attacker to take control over the Email application’s UI (e.g., display a malicious prompt to the user asking them to re-enter their email credentials) and also allows an attacker to abuse any of the privileges available to the mobile application.

CPENameOperatorVersion
kaioseq2.5
kaioseq1.0
kaioseq2.5.12.5

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.3%

Related for PRION:CVE-2019-14756