Lucene search

K
cveJpcertCVE-2024-28745
HistoryMar 18, 2024 - 4:15 a.m.

CVE-2024-28745

2024-03-1804:15:09
jpcert
web.nvd.nist.gov
39
cve-2024-28745
android
abema
nvd
security vulnerability
phishing attack

AI Score

6.7

Confidence

Low

EPSS

0

Percentile

9.0%

Improper export of Android application components issue exists in ‘ABEMA’ App for Android prior to 10.65.0 allowing another app installed on the user’s device to access an arbitrary URL on ‘ABEMA’ App for Android via Intent. If this vulnerability is exploited, an arbitrary website may be displayed on the app, and as a result, the user may become a victim of a phishing attack.

Affected configurations

Vulners
Node
abematv\,_inc.\'abema\'_app_for_androidRange<10.65.0
VendorProductVersionCPE
abematv\,_inc.\'abema\'_app_for_android*cpe:2.3:a:abematv\,_inc.:\'abema\'_app_for_android:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "AbemaTV, Inc.",
    "product": "'ABEMA' App for Android",
    "versions": [
      {
        "version": "prior to 10.65.0",
        "status": "affected"
      }
    ]
  }
]

AI Score

6.7

Confidence

Low

EPSS

0

Percentile

9.0%

Related for CVE-2024-28745