CVE-2019-14757
Last modified
CVE-2019-14757 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. An issue was discovered in KaiOS 2.5 and 2.5.1. The pre-installed Contacts application is vulnerable to HTML and JavaScript injection attacks. EPSS estimates a 0.83% chance of exploitation in the next 30 days.
Description
An issue was discovered in KaiOS 2.5 and 2.5.1. The pre-installed Contacts application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a vCard file to the victim that will inject HTML into the Contacts application (assuming the victim chooses to import the file). At a bare minimum, this allows an attacker to take control over the Contacts application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kaiostech | Kaios | 2.5 |
| Kaiostech | Kaios | 2.5.1 |
References
- https://www.nccgroup.trust/us/our-research/Third Party Advisory
- https://www.nccgroup.trust/us/our-research/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-14757?
How severe is CVE-2019-14757?
How do I fix CVE-2019-14757?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-14751NLTK Downloader before 3.4.5 is vulnerable to a directory tr…
- CVE-2019-14752SuiteCRM 7.10.x and 7.11.x before 7.10.20 and 7.11.8 has XSS…6.1
- CVE-2019-14753SICK FX0-GPNT00000 and FX0-GENT00000 devices through 3.4.0 h…7.5
- CVE-2019-14754Open-School 3.0, and Community Edition 2.3, allows SQL Injec…
- CVE-2019-14755The profile photo upload feature in Leaf Admin 61.9.0212.10 …
- CVE-2019-14756An issue was discovered in KaiOS 1.0, 2.5, and 2.5.12.5. The…6.1
- CVE-2019-14758An issue was discovered in KaiOS 2.5 and 2.5.1. The pre-inst…6.1
- CVE-2019-14759An issue was discovered in KaiOS 1.0, 2.5, and 2.5.1. The pr…4.4
- CVE-2019-1476An elevation of privilege vulnerability exists when Windows …7.8
- CVE-2019-14760An issue was discovered in KaiOS 2.5. The pre-installed Reco…4.4
- CVE-2019-14761An issue was discovered in KaiOS 2.5. The pre-installed Note…4.4
- CVE-2019-14763In the Linux kernel before 4.16.4, a double-locking error in…5.5
Are you affected by CVE-2019-14757?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
