Improper authorization in handler for custom URL scheme issue in 'ZOZOTOWN' App for Android versions prior to 7.39.6 allows an attacker to lead a user to access an arbitrary website via another application installed on the user's device. As a result, the user may become a victim of a phishing attack.
References
Configurations
No configuration.
History
21 Nov 2024, 09:20
Type | Values Removed | Values Added |
---|---|---|
References | () https://jvn.jp/en/jp/JVN37818611/ - |
03 Jul 2024, 02:01
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-939 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
20 Jun 2024, 12:44
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
19 Jun 2024, 05:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-19 05:15
Updated : 2024-11-21 09:20
NVD link : CVE-2024-35298
Mitre link : CVE-2024-35298
CVE.ORG link : CVE-2024-35298
JSON object : View
Products Affected
No product.
CWE
CWE-939
Improper Authorization in Handler for Custom URL Scheme