CVE-2023-40040
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in the MyCrops HiGrade "THC Testing & Cannabi" application 1.0.337 for Android. A remote attacker can start the camera feed via the com.cordovaplugincamerapreview.CameraActivity component in some situations. NOTE: this is only exploitable on Android versions that lack runtime permission checks, and of those only Android SDK 5.1.1 API 22 is consistent with the manifest. Thus, this applies only to Android Lollipop, affecting less than five percent of Android devices as of 2023.
Se descubrió un problema en la aplicación MyCrops HiGrade "THC Testing & Cannabi" 1.0.337 para Android. Un atacante remoto puede iniciar la transmisión de la cámara a través del componente com.cordovaplugincamerapreview.CameraActivity en algunas situaciones. NOTA: esto solo se puede explotar en versiones de Android que carecen de comprobaciones de permisos de tiempo de ejecución y, de ellas, solo Android SDK 5.1.1 API 22 es coherente con el manifiesto. Por lo tanto, esto se aplica sólo a Android Lollipop, y afectará a menos del cinco por ciento de los dispositivos Android a partir de 2023.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-08-08 CVE Reserved
- 2023-09-11 CVE Published
- 2024-09-17 EPSS Updated
- 2024-09-26 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-862: Missing Authorization
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://github.com/actuator/cve/blob/main/CVE-2023-40040 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mycrops Search vendor "Mycrops" | Higrade Search vendor "Mycrops" for product "Higrade" | 1.0.337 Search vendor "Mycrops" for product "Higrade" and version "1.0.337" | - |
Affected
| in | Google Search vendor "Google" | Android Search vendor "Google" for product "Android" | >= 5.0 <= 5.1.1 Search vendor "Google" for product "Android" and version " >= 5.0 <= 5.1.1" | - |
Safe
|