CVE-2024-45354: xiaomi shop application Webview has code execution vulnerability
Published Mar 27, 2025
·Updated
A code execution vulnerability exists in the Xiaomi shop applicationproduct. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code.
Affected Software
1 affected component
Xiaomi shop application
Event History
Mar 27, 2025
CVE Published
via MITRE·06:25 AM
Data Sourced
via MITRE·06:25 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-45354?
CVE-2024-45354 is classified as a critical severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2024-45354?
To fix CVE-2024-45354, update the Xiaomi shop application to the latest version that addresses the input validation issues.
3
Who is affected by CVE-2024-45354?
Users of the Xiaomi shop application are affected by CVE-2024-45354.
4
What can attackers do with CVE-2024-45354?
Attackers can exploit CVE-2024-45354 to execute arbitrary malicious code on vulnerable systems.
5
How was CVE-2024-45354 discovered?
CVE-2024-45354 was discovered through security analysis that identified improper input validation in the Xiaomi shop application.