'Yahoo! JAPAN' App for Android v2.3.1 to v3.161.1 and 'Yahoo! JAPAN' App for iOS v3.2.2 to v4.109.0 contain a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the WebView of 'Yahoo! JAPAN' App via other app installed on the user's device.
References
History

Wed, 06 Nov 2024 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2024-04-01T00:16:08.562Z

Updated: 2024-11-06T20:45:53.363Z

Reserved: 2024-03-13T00:41:43.890Z

Link: CVE-2024-28895

cve-icon Vulnrichment

Updated: 2024-08-02T01:03:50.243Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-01T01:15:46.890

Modified: 2024-11-06T21:35:05.843

Link: CVE-2024-28895

cve-icon Redhat

No data.