CVE-2018-20523

Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can read the user's cleartext browser history via an app.provider.query content://com.android.browser.searchhistory/searchhistory request.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
mistock_browser
10.2.4g:g
miredmi_7_firmware
-
miredmi_note_7_firmware
-
miredmi_note_6_pro_firmware
-
miredmi_6_firmware
-
miredmi_6a_firmware
-
miredmi_s2_firmware
-
miredmi_note_5_pro_firmware
-
miredmi_k20_pro_firmware
-
miredmi_k20_firmware
-
miredmi_7a_firmware
-
miredmi_go_firmware
-
miredmi_note_5_firmware
-
miredmi_y3_firmware
-
miredmi_note_7s_firmware
-
miredmi_s2_firmware
-
miredmi_4a_firmware
-
miredmi_note_4_firmware
-
miredmi_5_plus_firmware
-
miredmi_note_5a_prime_firmware
-
𝑥
= Vulnerable software versions