Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-26316

A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview's whitelist checking function allowing javascript protocol to be loaded and can be exploited by attackers to steal Xiaomi cloud service account's cookies.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 57.8%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2023-26316
  • Mi » Xiaomi Cloud » Version: N/A
    cpe:2.3:a:mi:xiaomi_cloud:-
  • Mi » Xiaomi Cloud » Version: 1.12.0.0.21
    cpe:2.3:a:mi:xiaomi_cloud:1.12.0.0.21
  • Mi » Xiaomi Cloud » Version: 1.12.0.0.25
    cpe:2.3:a:mi:xiaomi_cloud:1.12.0.0.25


Contact Us

Shodan ® - All rights reserved