CVE-2023-52381

CRITICAL

Huawei EMUI and HarmonyOS - Script Injection in Email Module

Title source: llm
STIX 2.1

Description

Script injection vulnerability in the email module.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.

Scores

CVSS v3 9.8
EPSS 0.0019
EPSS Percentile 41.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-94
Status published
Products (7)
huawei/emui 12.0.0
huawei/emui 13.0.0
huawei/harmonyos 2.0.0
huawei/harmonyos 2.1.0
huawei/harmonyos 3.0.0
huawei/harmonyos 3.1.0
huawei/harmonyos 4.0.0
Published Feb 18, 2024
Tracked Since Feb 18, 2026