Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x466-xhx8-frqr

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

Android App 'Mercari' (Japan version) prior to version 3.52.0 allows arbitrary method execution of a Java object by a remote attacker via a Man-In-The-Middle attack by using Java Reflection API of JavaScript code on WebView.

Android App 'Mercari' (Japan version) prior to version 3.52.0 allows arbitrary method execution of a Java object by a remote attacker via a Man-In-The-Middle attack by using Java Reflection API of JavaScript code on WebView.

EPSS

Процентиль: 81%
0.01475
Низкий

8.1 High

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 8.1
nvd
больше 5 лет назад

Android App 'Mercari' (Japan version) prior to version 3.52.0 allows arbitrary method execution of a Java object by a remote attacker via a Man-In-The-Middle attack by using Java Reflection API of JavaScript code on WebView.

EPSS

Процентиль: 81%
0.01475
Низкий

8.1 High

CVSS3

Дефекты

CWE-74