CVE-2023-26321

A path traversal vulnerability exists in the Xiaomi File Manager application product(international version). The vulnerability is caused by unfiltered special characters and can be exploited by attackers to overwrite and execute code in the file.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:mi:file_manager:1-210567:*:*:*:*:*:*:*

History

12 Sep 2024, 16:29

Type Values Removed Values Added
References () https://trust.mi.com/misrc/bulletins/advisory?cveId=541 - () https://trust.mi.com/misrc/bulletins/advisory?cveId=541 - Vendor Advisory
First Time Mi file Manager
Mi
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:mi:file_manager:1-210567:*:*:*:*:*:*:*
CWE CWE-22

28 Aug 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-28 08:15

Updated : 2025-03-25 16:15


NVD link : CVE-2023-26321

Mitre link : CVE-2023-26321


JSON object : View

Products Affected

mi

  • file_manager
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')