Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cgr9-p7j2-h64m

Опубликовано: 14 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 contains an exported component, PushDeepLinkActivity, which is accessible without authentication via ADB or malicious apps. This poses a risk of unintended access to application internals and can cause denial of service or logic abuse.

The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 contains an exported component, PushDeepLinkActivity, which is accessible without authentication via ADB or malicious apps. This poses a risk of unintended access to application internals and can cause denial of service or logic abuse.

EPSS

Процентиль: 40%
0.00179
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 6.5
nvd
6 месяцев назад

The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 contains an exported component, PushDeepLinkActivity, which is accessible without authentication via ADB or malicious apps. This poses a risk of unintended access to application internals and can cause denial of service or logic abuse.

EPSS

Процентиль: 40%
0.00179
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284