Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-23388

Опубликовано: 26 янв. 2024
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

Improper authorization in handler for custom URL scheme issue in "Mercari" App for Android prior to version 5.78.0 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mercari:mercari:*:*:*:*:*:android:*:*
Версия до 5.78.0 (исключая)

EPSS

Процентиль: 40%
0.00182
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-862
CWE-862

Связанные уязвимости

CVSS3: 6.1
github
больше 1 года назад

Improper authorization in handler for custom URL scheme issue in "Mercari" App for Android prior to version 5.78.0 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.

EPSS

Процентиль: 40%
0.00182
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-862
CWE-862