CVE-2017-8153

HIGH

Huawei VMall for Android < 1.5.8.5 - Privilege Escalation via Malicious App

Title source: llm
STIX 2.1

Description

Huawei VMall (for Android) with the versions before 1.5.8.5 have a privilege elevation vulnerability due to improper design. An attacker can trick users into installing a malicious app which can send out HTTP requests and execute JavaScript code in web pages without obtaining the Internet access permission. Successful exploit could lead to resource occupation or information leak.

References (1)

Core 1
Core References

Scores

CVSS v3 7.1
EPSS 0.0008
EPSS Percentile 24.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

Details

CWE
CWE-275
Status published
Products (2)
huawei/vmall < 1.5.8.5
Huawei Technologies Co., Ltd./VMall (for Android) The versions before VMall 1.5.8.5
Published Nov 22, 2017
Tracked Since Feb 18, 2026