CVE-2020-25204 Information
Feb 14, 2021
cve
Description
The God Kings application 0.60.1 for Android exposes a broadcast receiver to other apps called com.innogames.core.frontend.notifications.receivers.LocalNotificationBroadcastReceiver. The purpose of this broadcast receiver is to show an in-game push notification to the player. However the application does not enforce any authorization schema on the broadcast receiver allowing any application to send fully customizable in-game push notifications.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Reference
http://packetstormsecurity.com/files/159747/God-Kings-0.60.1-Notification-Spoofing.html
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
NONE
Base Severity
5.5
Share on: