Improper authorization in handler... CVE-2021-20835

5.0 AV AC AU C I A
发布: 2021-11-24
修订: 2024-11-21

Improper authorization in handler for custom URL scheme vulnerability in Android App 'Mercari (Merpay) - Marketplace and Mobile Payments App' (Japan version) versions prior to 4.49.1 allows a remote attacker to lead a user to access an arbitrary website and the website launches an arbitrary Activity of the app via the vulnerable App, which may result in Mercari account's access token being obtained.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息