lyhinslab.org
https://lyhinslab.org/index.php/2020/07/18/how-the-white-box-hacking-works-ok-google-i-wanna-pwn-this-app CVE-2020-22475
MEDIUM
Tasks 9.7.3 - Insecure Permissions
Record summary
CVE-2020-22475 has a selected CVSS score of 6.8 (medium); EIP currently links 1 catalogued exploit.
Description
"Tasks" application version before 9.7.3 is affected by insecure permissions. The VoiceCommandActivity application component allows arbitrary applications on a device to add tasks with no restrictions.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBTasks 9.7.3 - Insecure PermissionsExploitDB exploitby Lyhin\'s LabNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-22475 exploit-db.com
https://www.exploit-db.com/exploits/49563