Arbitrary Activity Launch Vulnerability in Settings Prior to SMR-May-2022 Release 1

Arbitrary Activity Launch Vulnerability in Settings Prior to SMR-May-2022 Release 1

CVE-2022-28781 · MEDIUM Severity

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Improper input validation in Settings prior to SMR-May-2022 Release 1 allows attackers to launch arbitrary activity with system privilege. The patch adds proper validation logic to check the caller.

Learn more about our Web Application Penetration Testing UK.