A session hijacking vulnerability has been detected in...
High severity
Unreviewed
Published
Dec 19, 2023
to the GitHub Advisory Database
•
Updated Dec 19, 2023
Description
Published by the National Vulnerability Database
Dec 19, 2023
Published to the GitHub Advisory Database
Dec 19, 2023
Last updated
Dec 19, 2023
A session hijacking vulnerability has been detected in the Imou Life application affecting version 6.7.0. This vulnerability could allow an attacker to hijack user accounts due to the QR code functionality not properly filtering codes when scanning a new device and directly running WebView without prompting or displaying it to the user. This vulnerability could trigger phishing attacks.
References