Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2021-40180
In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.searchContacts.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.002
EPSS Ranking
40.4%
CVSS Severity
CVSS v3 Score
7.5
References
https://arxiv.org/pdf/2205.15202.pdf
https://github.com/BESTICSP/Vulnerabilities-Related-to-Mini-Programs-Permissions/blob/main/WX%20applet%20contact%20permission%20vulnerability%20report.pdf
https://pan.baidu.com/s/116sAQvs1CEzCeIfpI1NZvA
https://pan.baidu.com/s/1RqMrZBruZZ4OHdnXUN5xDw
https://arxiv.org/pdf/2205.15202.pdf
https://github.com/BESTICSP/Vulnerabilities-Related-to-Mini-Programs-Permissions/blob/main/WX%20applet%20contact%20permission%20vulnerability%20report.pdf
https://pan.baidu.com/s/116sAQvs1CEzCeIfpI1NZvA
https://pan.baidu.com/s/1RqMrZBruZZ4OHdnXUN5xDw
Products affected by CVE-2021-40180
Tencent
»
Wechat
»
Version:
8.0.10
cpe:2.3:a:tencent:wechat:8.0.10
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved