CVE Feed

    Dashboard / CVE / CVE-2023-40040

    CVE-2023-40040

    An issue was discovered in the MyCrops HiGrade "THC Testing & Cannabi" application 1.0.337 for Android. A remote attacker can start the camera feed via the com.cordovaplugincamerapreview.CameraActivity component in some situations. NOTE: this is only exploitable on Android versions that lack runtime permission checks, and of those only Android SDK 5.1.1 API 22 is consistent with the manifest. Thus, this applies only to Android Lollipop, affecting less than five percent of Android devices as of 2023.

    Published:Sep 11, 2023
    Last Modified:Nov 21, 2024
    EPS:Sep 11, 2023
    EPSS Score:0.00081
    CVSS Score:5.3

    Affected Products

    Vendor
    Android
    Product
    Mycrops Higrade
    Vendor
    Google
    Product
    Android
    Vendor
    Mycrops
    Product
    Higrade

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High