CVE-2023-40121

All FrameworksAndroidCWE-OtherCVE-2023-40121

CVE-2023-40121

State: PUBLISHED · Published: 2023-10-27 · Updated: 2024-09-09 · Assigner: google_android
Description
In appendEscapedSQLString of DatabaseUtils.java, there is a possible SQL injection due to unsafe deserialization. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2023/40xxx/CVE-2023-40121.json