CVE-2023-6542

CVSS V2 None CVSS V3 None
Description
Due to lack of proper authorization checks in Emarsys SDK for Android, an attacker can call a particular activity and can forward himself web pages and/or deep links without any validation directly from the host application. On successful attack, an attacker could navigate to arbitrary URL including application deep links on the device.
Overview
  • CVE ID
  • CVE-2023-6542
  • Assigner
  • sap
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-12-12T01:36:22.773Z
  • Last Modified Date
  • 2023-12-12T01:36:22.773Z
History
Created Old Value New Value Data Type Notes
2024-06-25 07:04:32 Added to TrackCVE