CVE Published: 07/11/2023 |
CVE Updated: 12/09/2024 |
CVE Year: 2023 Source: Samsung Mobile |
Vendor: Samsung Mobile |
Product: Samsung Account Status : PUBLISHED
CVE-2023-42549 Description
Use of implicit intent for sensitive communication vulnerability in startNameValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
Metrics
CVSS Version: 3.1 |
Base Score: 5.5 MEDIUM Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N