First published: Thu Apr 21 2022(Updated: )
A business logic vulnerability exists in Mi App Store. The vulnerability is caused by incomplete permission checks of the products being bypassed, and an attacker can exploit the vulnerability to perform a local silent installation.
Credit: security@xiaomi.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mi Mi App Store | =4.12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-14121.
CVE-2020-14121 is a business logic vulnerability in Mi App Store that allows for local silent installation by bypassing permission checks.
The severity of CVE-2020-14121 is medium with a severity value of 5.5.
Version 4.12.2 of Mi App Store is affected by CVE-2020-14121.
You can find more information about CVE-2020-14121 at the following link: https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=146