Vulnerability Description
An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges cause a denial of service via the update_info field of the _default_.xml file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Egostudiogroup | Super Clean | 1.1.5 |
Related Weaknesses (CWE)
References
- http://www.egostudiogroup.com/Product
- https://apkpure.com/cn/super-clean-phone-cleaner/com.egostudio.clean/downloadProduct
- https://github.com/LianKee/SODA/blob/main/CVEs/CVE-2023-27652/CVE%20detail.mdExploitThird Party Advisory
- http://www.egostudiogroup.com/Product
- https://apkpure.com/cn/super-clean-phone-cleaner/com.egostudio.clean/downloadProduct
- https://github.com/LianKee/SODA/blob/main/CVEs/CVE-2023-27652/CVE%20detail.mdExploitThird Party Advisory
FAQ
What is CVE-2023-27652?
CVE-2023-27652 is a vulnerability with a CVSS score of 5.5 (MEDIUM). An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges cause a denial of service via the update_info field of the _default_.xml file.
How severe is CVE-2023-27652?
CVE-2023-27652 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-27652?
Check the references section above for vendor advisories and patch information. Affected products include: Egostudiogroup Super Clean.