Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
MicroMathematics version before commit 5c05ac8 contains a XML External Entity (XXE) vulnerability in SMathStudio files that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Specially crafted SMathStudio files. This vulnerability appears to have been fixed in after commit 5c05ac8.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MicroMathematics 安全漏洞
Vulnerability Description
MicroMathematics是一款基于Android平台的科学计算器应用程序。该程序支持多种常用的数学计算,支持数据导入和导出等功能。 MicroMathematics commit 5c05ac8之前版本中的SMathStudio文件存在XML外部实体注入漏洞。攻击者可借助特制的SMathStudio文件利用该漏洞泄露敏感数据,造成拒绝服务,实施服务器端请求伪造攻击或扫描端口。
CVSS Information
N/A
Vulnerability Type
N/A