CVE Published: 16/08/2023 |
CVE Updated: 08/10/2024 |
CVE Year: 2023 Source: jpcert |
Vendor: Recruit Co., Ltd. |
Product: "Rikunabi NEXT" App for Android Status : PUBLISHED
CVE-2023-39507 Description
Improper authorization in the custom URL scheme handler in "Rikunabi NEXT" App for Android prior to ver. 11.5.0 allows a malicious intent to lead the vulnerable App to access an arbitrary website.