CVE-2021-40180

In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.searchContacts.
References
Link Resource
https://arxiv.org/pdf/2205.15202.pdf Mitigation Technical Description Third Party Advisory
https://github.com/BESTICSP/Vulnerabilities-Related-to-Mini-Programs-Permissions/blob/main/WX%20applet%20contact%20permission%20vulnerability%20report.pdf Exploit Third Party Advisory
https://pan.baidu.com/s/116sAQvs1CEzCeIfpI1NZvA Exploit Permissions Required Third Party Advisory
https://pan.baidu.com/s/1RqMrZBruZZ4OHdnXUN5xDw Exploit Permissions Required Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:tencent:wechat:8.0.10:*:*:*:*:android:*:*
cpe:2.3:a:tencent:wechat:8.0.10:*:*:*:*:iphone_os:*:*

History

04 Aug 2022, 16:17

Type Values Removed Values Added
First Time Tencent
Tencent wechat
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-200
CPE cpe:2.3:a:tencent:wechat:8.0.10:*:*:*:*:iphone_os:*:*
cpe:2.3:a:tencent:wechat:8.0.10:*:*:*:*:android:*:*
References (MISC) https://github.com/BESTICSP/Vulnerabilities-Related-to-Mini-Programs-Permissions/blob/main/WX%20applet%20contact%20permission%20vulnerability%20report.pdf - (MISC) https://github.com/BESTICSP/Vulnerabilities-Related-to-Mini-Programs-Permissions/blob/main/WX%20applet%20contact%20permission%20vulnerability%20report.pdf - Exploit, Third Party Advisory
References (MISC) https://pan.baidu.com/s/1RqMrZBruZZ4OHdnXUN5xDw - (MISC) https://pan.baidu.com/s/1RqMrZBruZZ4OHdnXUN5xDw - Exploit, Permissions Required, Third Party Advisory
References (MISC) https://pan.baidu.com/s/116sAQvs1CEzCeIfpI1NZvA - (MISC) https://pan.baidu.com/s/116sAQvs1CEzCeIfpI1NZvA - Exploit, Permissions Required, Third Party Advisory
References (MISC) https://arxiv.org/pdf/2205.15202.pdf - (MISC) https://arxiv.org/pdf/2205.15202.pdf - Mitigation, Technical Description, Third Party Advisory

01 Aug 2022, 12:15

Type Values Removed Values Added
References
  • (MISC) https://github.com/BESTICSP/Vulnerabilities-Related-to-Mini-Programs-Permissions/blob/main/WX%20applet%20contact%20permission%20vulnerability%20report.pdf -

26 Jul 2022, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-07-26 23:15

Updated : 2023-12-10 14:35


NVD link : CVE-2021-40180

Mitre link : CVE-2021-40180

CVE.ORG link : CVE-2021-40180


JSON object : View

Products Affected

tencent

  • wechat
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor