CVE-2018-14066

The content://wappush content provider in com.android.provider.telephony, as found in some custom ROMs for Android phones, allows SQL injection. One consequence is that an application without the READ_SMS permission can read SMS messages. This affects Infinix X571 phones, as well as various Lenovo phones (such as the A7020) that have since been fixed by Lenovo.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:google:android:7.0:*:*:*:*:*:*:*
cpe:2.3:h:infinixmobility:infinix_x571:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:lenovo_a7020:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-07-15 16:29

Updated : 2023-12-10 12:44


NVD link : CVE-2018-14066

Mitre link : CVE-2018-14066

CVE.ORG link : CVE-2018-14066


JSON object : View

Products Affected

lenovo

  • lenovo_a7020

infinixmobility

  • infinix_x571

google

  • android
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')