{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-23T00:16:19.049","vulnerabilities":[{"cve":{"id":"CVE-2020-7705","sourceIdentifier":"report@snyk.io","published":"2020-08-24T18:15:10.143","lastModified":"2026-06-17T03:25:17.910","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"This affects the package MintegralAdSDK from 0.0.0. The SDK distributed by the company contains malicious functionality that tracks any URL opened by the app and reports it back to the company, along with performing advertisement attribution fraud. Mintegral can remotely activate hooks on the UIApplication, openURL, SKStoreProductViewController, loadProductWithParameters and NSURLProtocol methods along with anti-debug and proxy detection protection. If those hooks are active MintegralAdSDK sends obfuscated data about every opened URL in an application to their servers. Note that the malicious functionality is enabled even if the SDK was not enabled to serve ads."},{"lang":"es","value":"Esto afecta al paquete MintegralAdSDK desde la versión 0.0.0. El SDK distribuido por la empresa contiene una funcionalidad maliciosa que rastrea cualquier URL abierta por la aplicación y la reporta a la empresa, además de llevar a cabo un fraude de atribución publicitaria. Mintegral puede remotamente activar hooks en los métodos UIApplication, openURL, SKStoreProductViewController, loadProductWithParameters y NSURLProtocol junto con la protección de detección de proxy y anti-debug. Si esos hooks están activos, MintegralAdSDK envía datos ofuscados sobre cada URL abierta en una aplicación hacia sus servidores. Tome en cuenta que la funcionalidad maliciosa está habilitada incluso si el SDK no estaba habilitado para publicar anuncios."}],"affected":[{"source":"report@snyk.io","affectedData":[{"vendor":"n/a","product":"MintegralAdSDK","versions":[{"version":"0.0.0","lessThan":"unspecified","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"report@snyk.io","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1021"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mintegral:mintegraladsdk:*:*:*:*:*:*:*:*","versionStartIncluding":"0.0.0","matchCriteriaId":"A3713524-33F9-462A-8FC0-BE573B08DA10"}]}]}],"references":[{"url":"https://snyk.io/blog/sourmint-malicious-code-ad-fraud-and-data-leak-in-ios/","source":"report@snyk.io","tags":["Third Party Advisory"]},{"url":"https://snyk.io/research/sour-mint-malicious-sdk/","source":"report@snyk.io","tags":["Third Party Advisory"]},{"url":"https://snyk.io/vuln/SNYK-COCOAPODS-MINTEGRALADSDK-598852","source":"report@snyk.io","tags":["Third Party Advisory"]},{"url":"https://snyk.io/blog/sourmint-malicious-code-ad-fraud-and-data-leak-in-ios/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://snyk.io/research/sour-mint-malicious-sdk/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://snyk.io/vuln/SNYK-COCOAPODS-MINTEGRALADSDK-598852","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}