CVE Published: 24/11/2021 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: jpcert |
Vendor: Mercari, Inc. |
Product: Android App \'Mercari (Merpay) - Marketplace and Mobile Payments App\' (Japan version) Status : PUBLISHED
CVE-2021-20835 Description
Improper authorization in handler for custom URL scheme vulnerability in Android App \'Mercari (Merpay) - Marketplace and Mobile Payments App\' (Japan version) versions prior to 4.49.1 allows a remote attacker to lead a user to access an arbitrary website and the website launches an arbitrary Activity of the app via the vulnerable App, which may result in Mercari account\'s access token being obtained.