CVE-2024-37575

The Mister org.mistergroup.shouldianswer application 1.4.264 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the org.mistergroup.shouldianswer.ui.default_dialer.DefaultDialerActivity component.
Configurations

No configuration.

History

11 Dec 2024, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
Summary
  • (es) La aplicación Mister org.mistergroup.shouldianswer 1.4.264 para Android permite que cualquier aplicación instalada (sin permisos) realice llamadas telefónicas sin interacción del usuario enviando una intención manipulada a través del componente org.mistergroup.shouldianswer.ui.default_dialer.DefaultDialerActivity.
CWE CWE-281

Information

Published : 2024-12-04 16:15

Updated : 2024-12-11 16:15


NVD link : CVE-2024-37575

Mitre link : CVE-2024-37575

CVE.ORG link : CVE-2024-37575


JSON object : View

Products Affected

No product.

CWE
CWE-281

Improper Preservation of Permissions