Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mwxg-grq3-792c

Опубликовано: 17 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

The com.solarized.firedown (aka Solarized FireDown Browser & Downloader) application 1.0.76 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. com.solarized.firedown.IntentActivity uses a WebView component to display web content and doesn't adequately sanitize the URI or any extra data passed in the intent by any installed application (with no permissions).

The com.solarized.firedown (aka Solarized FireDown Browser & Downloader) application 1.0.76 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. com.solarized.firedown.IntentActivity uses a WebView component to display web content and doesn't adequately sanitize the URI or any extra data passed in the intent by any installed application (with no permissions).

EPSS

Процентиль: 84%
0.0214
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 6.3
nvd
больше 1 года назад

The com.solarized.firedown (aka Solarized FireDown Browser & Downloader) application 1.0.76 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. com.solarized.firedown.IntentActivity uses a WebView component to display web content and doesn't adequately sanitize the URI or any extra data passed in the intent by any installed application (with no permissions).

EPSS

Процентиль: 84%
0.0214
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-94