PT-2023-32690 · Emarsys · Emarsys Sdk For Android

CVE-2023-6542

·

Publicado

2022-02-01

·

Atualizado

2025-10-31

CVSS v3.1

7.1

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SAP Emarsys SDK for Android (affected versions not specified)
Description The issue is due to a lack of proper authorization checks in the Emarsys SDK for Android, allowing an attacker to call a particular activity and forward web pages and/or deep links without validation directly from the host application. On a successful attack, an attacker could navigate to an arbitrary URL, including application deep links on the device. This could potentially lead to sensitive data leaks from an app's private data directory and allow loading remote contents into an app overlay.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-05011
CVE-2023-6542

Produtos afetados

Emarsys Sdk For Android