CVE-2023-40040: Medium severity mycrops higrade vulnerability
An issue was discovered in the MyCrops HiGrade "THC Testing & Cannabi" application 1.0.337 for Android. A remote attacker can start the camera feed via the com.cordovaplugincamerapreview.CameraActivity component in some situations. NOTE: this is only exploitable on Android versions that lack runtime permission checks, and of those only Android SDK 5.1.1 API 22 is consistent with the manifest. Thus, this applies only to Android Lollipop, affecting less than five percent of Android devices as of 2023.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-40040.
What is the severity of CVE-2023-40040?
The severity of CVE-2023-40040 is medium.
What is the affected software for CVE-2023-40040?
The affected software for CVE-2023-40040 is MyCrops HiGrade application version 1.0.337 for Android.
How can a remote attacker exploit CVE-2023-40040?
A remote attacker can start the camera feed via the com.cordovaplugincamerapreview.CameraActivity component in some situations.
Is CVE-2023-40040 exploitable on all Android versions?
No, CVE-2023-40040 is only exploitable on Android versions that lack runtime.