HomeDefault status
unaffected
v1.3.0.002
affected
Description
Cross-Site Scripting (XSS) in GeniexWebView component in Transsion AI Assistant Lifestyle application (com.transsion.aiassistantlifestyle) all versions on Android allows remote attacker to execute arbitrary JavaScript in the WebView context via crafted web_action_data URL parameter.
Problem types
CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')
Product status
v1.3.0.002
References
security.tecno.com/SRC/securityUpdates