CVE-2023-28131

CVSS V2 None CVSS V3 None
Description
A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the "Expo AuthSession Redirect Proxy" for social sign-in. This can be achieved once a victim clicks a malicious link. The link itself may be sent to the victim in various ways (including email, text message, an attacker-controlled website, etc).
Overview
  • CVE ID
  • CVE-2023-28131
  • Assigner
  • cve@checkpoint.com
  • Vulnerability Status
  • Received
  • Published Version
  • 2023-04-24T05:15:08
  • Last Modified Date
  • 2023-04-24T05:15:08
History
Created Old Value New Value Data Type Notes
2023-04-24 06:00:55 Added to TrackCVE