Loading HuntDB...

GHSA-qcjm-2565-959w

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

An issue was discovered in the MyCrops HiGrade "THC Testing & Cannabi" application 1.0.337 for Android. A remote attacker can start the camera feed via the com.cordovaplugincamerapreview.CameraActivity component in some situations. NOTE: this is only exploitable on Android versions that lack runtime permission checks, and of those only Android SDK 5.1.1 API 22 is consistent with the manifest. Thus, this applies only to Android Lollipop, affecting less than five percent of Android devices as of 2023.

Related CVEs

Key Information

GHSA ID
GHSA-qcjm-2565-959w
Published
September 11, 2023 6:30 AM
Last Modified
April 4, 2024 7:34 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 4, 2025 6:27 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.