CVE-2019-9140 Information

Description

When processing Deeplink scheme Happypoint mobile app 6.3.19 and earlier versions doesn’t check Deeplink URL correctly. This could lead to javascript code execution url redirection sensitive information disclosure. An attacker can exploit this issue by enticing an unsuspecting user to open a specific malicious URL.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Reference

https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35103 When processing Deeplink scheme Happypoint mobile app 6.3.19 and earlier versions doesn’t check Deeplink URL correctly. This could lead to javascript code execution url redirection sensitive information disclosure. An attacker can exploit this issue by enticing an unsuspecting user to open a specific malicious URL.

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

NONE

Base Severity

8.1

Share on: