Vulnerability Description
In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.searchContacts.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tencent | 8.0.10 |
Related Weaknesses (CWE)
References
- https://arxiv.org/pdf/2205.15202.pdfMitigationTechnical DescriptionThird Party Advisory
- https://github.com/BESTICSP/Vulnerabilities-Related-to-Mini-Programs-PermissionsExploitThird Party Advisory
- https://pan.baidu.com/s/116sAQvs1CEzCeIfpI1NZvAExploitPermissions RequiredThird Party Advisory
- https://pan.baidu.com/s/1RqMrZBruZZ4OHdnXUN5xDwExploitPermissions RequiredThird Party Advisory
- https://arxiv.org/pdf/2205.15202.pdfMitigationTechnical DescriptionThird Party Advisory
- https://github.com/BESTICSP/Vulnerabilities-Related-to-Mini-Programs-PermissionsExploitThird Party Advisory
- https://pan.baidu.com/s/116sAQvs1CEzCeIfpI1NZvAExploitPermissions RequiredThird Party Advisory
- https://pan.baidu.com/s/1RqMrZBruZZ4OHdnXUN5xDwExploitPermissions RequiredThird Party Advisory
FAQ
What is CVE-2021-40180?
CVE-2021-40180 is a vulnerability with a CVSS score of 7.5 (HIGH). In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.searchContacts.
How severe is CVE-2021-40180?
CVE-2021-40180 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-40180?
Check the references section above for vendor advisories and patch information. Affected products include: Tencent Wechat.