Vulnerabilities > CVE-2020-14130 - Exposure of Resource to Wrong Sphere vulnerability in MI Xiaomi

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
mi
CWE-668

Summary

Some js interfaces in the Xiaomi community were exposed, causing sensitive functions to be maliciously called on Xiaomi community app Affected Version <3.0.210809

Vulnerable Configurations

Part Description Count
Application
Mi
1

Common Weakness Enumeration (CWE)