Security Advisory

CVE-2019-10875

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-04-05 12:36:49
Last updated 2024-08-04 22:32:02
Assigner mitre
State PUBLISHED

Description

A URL spoofing vulnerability was found in all international versions of Xiaomi Mi browser 10.5.6-g (aka the MIUI native browser) and Mint Browser 1.5.3 due to the way they handle the "q" query parameter. The portion of an https URL before the ?q= substring is not shown to the user.