A vulnerability, which was classified as problematic, has been found in Weee RICEPO App 6.17.77 on Android. This issue affects some unknown processing of the file AndroidManifest.xml of the component com.ricepo.app. The manipulation leads to improper export of android application components. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
History

Tue, 16 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Sayweee
Sayweee ricepo
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:sayweee:ricepo:6.17.77:*:*:*:*:android:*:*
Vendors & Products Sayweee
Sayweee ricepo

Tue, 12 Aug 2025 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Weee
Weee ricepo App
Vendors & Products Google
Google android
Weee
Weee ricepo App

Mon, 11 Aug 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 09 Aug 2025 05:15:00 +0000

Type Values Removed Values Added
Description A vulnerability, which was classified as problematic, has been found in Weee RICEPO App 6.17.77 on Android. This issue affects some unknown processing of the file AndroidManifest.xml of the component com.ricepo.app. The manipulation leads to improper export of android application components. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Weee RICEPO App com.ricepo.app AndroidManifest.xml improper export of android application components
Weaknesses CWE-926
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-08-09T05:02:05.495Z

Updated: 2025-08-11T18:33:45.620Z

Reserved: 2025-08-08T08:58:52.773Z

Link: CVE-2025-8745

cve-icon Vulnrichment

Updated: 2025-08-11T18:12:03.660Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-09T05:15:29.473

Modified: 2025-09-16T16:06:37.280

Link: CVE-2025-8745

cve-icon Redhat

No data.