CVE detail
CVE-2023-26316 — CVE-2023-26316
Published 2023-08-02 · Modified 2026-06-17 · Vendor mi · Product xiaomi_cloud · Source nvd
MEDIUM
severity
CVSS-derived band
0.0035
EPSS probability
exploitation probability, 30d
28.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview's whitelist checking function allowing javascript protocol to be loaded and can be exploited by attackers to steal Xiaomi cloud service account's cookies.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References