Due to lack of proper authorization checks in Emarsys SDK for Android, an attacker can call a particular activity and can forward himself web pages and/or deep links without any validation directly from the host application. On successful attack, an attacker could navigate to arbitrary URL including application deep links on the device.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: sap
Published: 2023-12-12T01:36:22.773Z
Updated: 2024-08-02T08:35:13.594Z
Reserved: 2023-12-06T03:42:15.409Z
Link: CVE-2023-6542
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-12-12T02:15:09.347
Modified: 2024-11-21T08:44:03.740
Link: CVE-2023-6542
Redhat
No data.