CVE Published: 02/08/2023 |
CVE Updated: 27/09/2024 |
CVE Year: 2023 Source: Xiaomi |
Vendor: n/a |
Product: Xiaomi cloud service Application Status : PUBLISHED
CVE-2023-26316 Description
A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview\'s whitelist checking function allowing javascript protocol to be loaded and can be exploited by attackers to steal Xiaomi cloud service account\'s cookies.