Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-20144
HistoryJun 15, 2022 - 2:15 p.m.

Design/Logic Flaw

2022-06-1514:15:00
PRIOn knowledge base
www.prio-n.com
5

0.0004 Low

EPSS

Percentile

5.1%

In multiple functions of AvatarPhotoController.java, there is a possible access to content owned by system content providers due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-250637906

CPENameOperatorVersion
androideq10.0
androideq11.0

0.0004 Low

EPSS

Percentile

5.1%

Related for PRION:CVE-2022-20144