Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-51219

Опубликовано: 03 июн. 2024
Источник: nvd
CVSS3: 9.6
EPSS Низкий

Описание

A deep link validation issue in KakaoTalk 10.4.3 allowed a remote adversary to direct users to run any attacker-controlled JavaScript within a WebView. The impact was further escalated by triggering another WebView that leaked its access token in a HTTP request header. Ultimately, this access token could be used to take over another user's account and read her/his chat messages.

EPSS

Процентиль: 76%
0.00917
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.5
github
больше 1 года назад

A deep link validation issue in KakaoTalk 10.4.3 allowed a remote adversary to direct users to run any attacker-controller JavaScript within a WebView. The impact was further escalated by triggering another WebView that leaked its access token in a HTTP request header. Ultimately, this access token could be used to takeover another user's account and read her/his chat messages.

EPSS

Процентиль: 76%
0.00917
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-79