CVE Published: 09/07/2020 |
CVE Updated: 04/08/2024 |
CVE Year: 2020 Source: jpcert |
Vendor: Mercari, Inc. |
Product: Android App \'Mercari\' (Japan version) Status : PUBLISHED
CVE-2020-5604 Description
Android App \'Mercari\' (Japan version) prior to version 3.52.0 allows arbitrary method execution of a Java object by a remote attacker via a Man-In-The-Middle attack by using Java Reflection API of JavaScript code on WebView.