Описание
Improper authorization in handler for custom URL scheme vulnerability in Lemon8 App for Android versions prior to 3.3.5 and Lemon8 App for iOS versions prior to 3.3.5 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.
Ссылки
- ProductThird Party Advisory
- Third Party Advisory
- ProductThird Party Advisory
- ProductThird Party Advisory
- Third Party Advisory
- ProductThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.3.5 (исключая)Версия до 3.3.5 (исключая)
Одно из
cpe:2.3:a:lemon8_project:lemon8:*:*:*:*:*:android:*:*
cpe:2.3:a:lemon8_project:lemon8:*:*:*:*:*:iphone_os:*:*
EPSS
Процентиль: 61%
0.00416
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-862
CWE-862
Связанные уязвимости
CVSS3: 6.5
github
больше 3 лет назад
Improper authorization in handler for custom URL scheme vulnerability in Lemon8 App for Android versions prior to 3.3.5 and Lemon8 App for iOS versions prior to 3.3.5 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.
EPSS
Процентиль: 61%
0.00416
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-862
CWE-862