← Back

CVE-2018-14066

nvd nist
Published: Jul 15, 2018Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

The content://wappush content provider in com.android.provider.telephony, as found in some custom ROMs for Android phones, allows SQL injection. One consequence is that an application without the READ_SMS permission can read SMS messages. This affects Infinix X571 phones, as well as various Lenovo phones (such as the A7020) that have since been fixed by Lenovo.

Affected (2)

Products: Google: Android
1 product
Android
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 7.0
Running on/withPlatform Versions
Infinixmobility
Infinix X571
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 6.0
Running on/withPlatform Versions
Lenovo
Lenovo A7020
All versions

References (2)

Timeline

No history available yet.