CVE Feed

    Dashboard / CVE / CVE-2019-10875

    CVE-2019-10875

    A URL spoofing vulnerability was found in all international versions of Xiaomi Mi browser 10.5.6-g (aka the MIUI native browser) and Mint Browser 1.5.3 due to the way they handle the "q" query parameter. The portion of an https URL before the ?q= substring is not shown to the user.

    Published:Apr 5, 2019
    Last Modified:Nov 21, 2024
    EPS:Apr 5, 2019
    EPSS Score:0.00725
    CVSS Score:6.5

    Affected Products

    Vendor
    Mi
    Product
    Mi Browser
    Vendor
    Mi
    Product
    Mint Browser

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High