PT-2023-32690 · Emarsys · Emarsys Sdk For Android
CVE-2023-6542
·
Publicado
2022-02-01
·
Atualizado
2025-10-31
CVSS v3.1
7.1
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SAP Emarsys SDK for Android (affected versions not specified)
Description
The issue is due to a lack of proper authorization checks in the Emarsys SDK for Android, allowing an attacker to call a particular activity and forward web pages and/or deep links without validation directly from the host application. On a successful attack, an attacker could navigate to an arbitrary URL, including application deep links on the device. This could potentially lead to sensitive data leaks from an app's private data directory and allow loading remote contents into an app overlay.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Incorrect Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Emarsys Sdk For Android