Exploitation Summary
EIP tracks 1 public exploit for CVE-2024-23727. PoCs published by actuator.
AI-analyzed exploit summary The repository provides a detailed technical analysis of CVE-2024-23727, an exported WebView activity vulnerability in YI IoT's 'com.yunyi.smartcamera' app. It includes proof-of-concept code snippets for ADB and Java-based exploitation, demonstrating how arbitrary JavaScript execution can be achieved.
Description
The YI Smart Kami Vision com.kamivision.yismart application through 1.0.0_20231219 for Android allows a remote attacker to execute arbitrary JavaScript code via an implicit intent to the com.ants360.yicamera.activity.WebViewActivity component.
Exploits (1)
The repository provides a detailed technical analysis of CVE-2024-23727, an exported WebView activity vulnerability in YI IoT's 'com.yunyi.smartcamera' app. It includes proof-of-concept code snippets for ADB and Java-based exploitation, demonstrating how arbitrary JavaScript execution can be achieved.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H