Vulnerability Description
The YI Smart Kami Vision com.kamivision.yismart application through 1.0.0_20231219 for Android allows a remote attacker to execute arbitrary JavaScript code via an implicit intent to the com.ants360.yicamera.activity.WebViewActivity component.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/actuator/yi/blob/main/com.kamivision.yismart.V1.0.0_20231219.
- https://github.com/actuator/yi/blob/main/com.kamivision.yismart.V1.0.0_20231219.
FAQ
What is CVE-2024-23727?
CVE-2024-23727 is a vulnerability with a CVSS score of 8.4 (HIGH). The YI Smart Kami Vision com.kamivision.yismart application through 1.0.0_20231219 for Android allows a remote attacker to execute arbitrary JavaScript code via an implicit intent to the com.ants360.y...
How severe is CVE-2024-23727?
CVE-2024-23727 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-23727?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.