CVE-2024-28745 Vulnerability Details

  /     /     /  

CVE-2024-28745 Metadata Quick Info

CVE Published: 18/03/2024 | CVE Updated: 19/11/2024 | CVE Year: 2024
Source: jpcert | Vendor: AbemaTV, Inc. | Product: \'ABEMA\' App for Android
Status : PUBLISHED

CVE-2024-28745 Description

Improper export of Android application components issue exists in \'ABEMA\' App for Android prior to 10.65.0 allowing another app installed on the user\'s device to access an arbitrary URL on \'ABEMA\' App for Android via Intent. If this vulnerability is exploited, an arbitrary website may be displayed on the app, and as a result, the user may become a victim of a phishing attack.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Improper Export of Android Application Components
Source: AbemaTV, Inc.

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).