Unrated severityNVD Advisory· Published Jul 26, 2022· Updated Aug 4, 2024
CVE-2021-40180
CVE-2021-40180
Description
In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.searchContacts.
Affected products
2- WeChat/WeChat applicationdescription
Patches
Vulnerability mechanics
References
4- arxiv.org/pdf/2205.15202.pdfmitrex_refsource_MISC
- github.com/BESTICSP/Vulnerabilities-Related-to-Mini-Programs-Permissions/blob/main/WX%20applet%20contact%20permission%20vulnerability%20report.pdfmitrex_refsource_MISC
- pan.baidu.com/s/116sAQvs1CEzCeIfpI1NZvAmitrex_refsource_MISC
- pan.baidu.com/s/1RqMrZBruZZ4OHdnXUN5xDwmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.