Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-42471

Опубликовано: 11 сент. 2023
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

The wave.ai.browser application through 1.0.35 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. It contains a manifest entry that exports the wave.ai.browser.ui.splash.SplashScreen activity. This activity uses a WebView component to display web content and doesn't adequately validate or sanitize the URI or any extra data passed in the intent by a third party application (with no permissions).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wave-ai:wave:*:*:*:*:*:android:*:*
Версия до 1.0.35 (включая)

EPSS

Процентиль: 86%
0.03016
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9.8
github
больше 2 лет назад

The wave.ai.browser application through 1.0.35 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. It contains a manifest entry that exports the wave.ai.browser.ui.splash.SplashScreen activity. This activity uses a WebView component to display web content and doesn't adequately validate or sanitize the URI or any extra data passed in the intent by a third party application (with no permissions).

EPSS

Процентиль: 86%
0.03016
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94