CVE-2019-10875
Xiaomi Mi Browser / Mint Browser URL Spoofing
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
A URL spoofing vulnerability was found in all international versions of Xiaomi Mi browser 10.5.6-g (aka the MIUI native browser) and Mint Browser 1.5.3 due to the way they handle the "q" query parameter. The portion of an https URL before the ?q= substring is not shown to the user.
Se ha detectado una vulnerabilidad de suplantación de URL en todas las versiones internacionales del navegador de Xiaomi Mi (también conocido como el navegador nativo MIUI), en su versión 10.5.6-g, y de Mint Browser, en su versión 1.5.3, en la manera en la que gestionan el parámetro de consultas "q". La porción de una URL https antes de la subcadena ?q= no se muestra al usuario.
Xiaomi Mi Browser version 10.5.6-g and Mint Browser version 1.5.3 suffer from a URL spoofing vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-04-04 CVE Reserved
- 2019-04-05 CVE Published
- 2019-04-11 First Exploit
- 2024-08-04 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-290: Authentication Bypass by Spoofing
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/152497/Xiaomi-Mi-Browser-Mint-Browser-URL-Spoofing.html | Third Party Advisory |
|
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/152497 | 2019-04-11 | |
https://thehackernews.com/2019/04/xiaomi-browser-vulnerability.html | 2024-08-04 | |
https://www.andmp.com/2019/04/xiaomi-url-spoofing-w-ssl-vulnerability.html | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mi Search vendor "Mi" | Mi Browser Search vendor "Mi" for product "Mi Browser" | 10.5.6-g Search vendor "Mi" for product "Mi Browser" and version "10.5.6-g" | - |
Affected
| ||||||
Mi Search vendor "Mi" | Mint Browser Search vendor "Mi" for product "Mint Browser" | 1.5.3 Search vendor "Mi" for product "Mint Browser" and version "1.5.3" | - |
Affected
|