Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9phr-845q-6wwg

Опубликовано: 24 окт. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Improper authorization in handler for custom URL scheme vulnerability in Lemon8 App for Android versions prior to 3.3.5 and Lemon8 App for iOS versions prior to 3.3.5 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.

Improper authorization in handler for custom URL scheme vulnerability in Lemon8 App for Android versions prior to 3.3.5 and Lemon8 App for iOS versions prior to 3.3.5 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.

EPSS

Процентиль: 61%
0.00416
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-862
CWE-863

Связанные уязвимости

CVSS3: 6.5
nvd
больше 3 лет назад

Improper authorization in handler for custom URL scheme vulnerability in Lemon8 App for Android versions prior to 3.3.5 and Lemon8 App for iOS versions prior to 3.3.5 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.

EPSS

Процентиль: 61%
0.00416
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-862
CWE-863