Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xx65-34vr-mqrj

Опубликовано: 26 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

Improper authorization in handler for custom URL scheme issue in "Mercari" App for Android prior to version 5.78.0 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.

Improper authorization in handler for custom URL scheme issue in "Mercari" App for Android prior to version 5.78.0 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.

EPSS

Процентиль: 40%
0.00182
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 6.1
nvd
больше 1 года назад

Improper authorization in handler for custom URL scheme issue in "Mercari" App for Android prior to version 5.78.0 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.

EPSS

Процентиль: 40%
0.00182
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-862