CVE-2022-20517
published 2022-12-16CVE-2022-20517: In getMessagesByPhoneNumber of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.21%
11.4th percentile
In getMessagesByPhoneNumber of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224769956
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| platform | packages_providers_telephonyprovider | >= 13:0 < 13:2022-12-01 | 13:2022-12-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android 13.0 MmsSmsProvider.java getMessagesByPhoneNumber information disclosure (A-224769956 / EUVD-2022-25777)
vuldb·2026-04-20·CVSS 5.5
CVE-2022-20517 [MEDIUM] Google Android 13.0 MmsSmsProvider.java getMessagesByPhoneNumber information disclosure (A-224769956 / EUVD-2022-25777)
A vulnerability labeled as problematic has been found in Google Android 13.0. Affected by this issue is the function getMessagesByPhoneNumber of the file MmsSmsProvider.java. The manipulation results in information disclosure.
This vulnerability is known as CVE-2022-20517. Attacking locally is a requirement. No exploit is available.
It is best practice to apply a patch to resolve this issue.
GHSA
GHSA-f849-jc2j-f4g4: In getMessagesByPhoneNumber of MmsSmsProvider
ghsa_unreviewed·2022-12-20
CVE-2022-20517 [MEDIUM] CWE-89 GHSA-f849-jc2j-f4g4: In getMessagesByPhoneNumber of MmsSmsProvider
In getMessagesByPhoneNumber of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224769956
OSV
CVE-2022-20517: In getMessagesByPhoneNumber of MmsSmsProvider
osv·2022-12-01
CVE-2022-20517 CVE-2022-20517: In getMessagesByPhoneNumber of MmsSmsProvider
In getMessagesByPhoneNumber of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-16
Published