ZeroHour

CVE-2023-6913

CVSS 3.1
8.1 high
EPSS
<1%p52
Published
()
Modified
Description

A session hijacking vulnerability has been detected in the Imou Life application affecting version 6.7.0. This vulnerability could allow an attacker to hijack user accounts due to the QR code functionality not properly filtering codes when scanning a new device and directly running WebView without prompting or displaying it to the user. This vulnerability could trigger phishing attacks.

Vendors
imoulife
Products
imou life
Weakness
CWE-384
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.