Lucene search

K
cve[email protected]CVE-2024-28895
HistoryApr 01, 2024 - 1:15 a.m.

CVE-2024-28895

2024-04-0101:15:46
web.nvd.nist.gov
6
yahoo! japan
android
ios
cross-site scripting
vulnerability
webview
arbitrary script
nvd

5.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

‘Yahoo! JAPAN’ App for Android v2.3.1 to v3.161.1 and ‘Yahoo! JAPAN’ App for iOS v3.2.2 to v4.109.0 contain a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the WebView of ‘Yahoo! JAPAN’ App via other app installed on the user’s device.

Affected configurations

Vulners
Node
ly_corporation\'yahoo\!_japan\'_app_for_androidRange2.3.13.161.1
OR
ly_corporation\'yahoo\!_japan\'_app_for_iosRange3.2.24.109.0

CNA Affected

[
  {
    "vendor": "LY Corporation",
    "product": "'Yahoo! JAPAN' App for Android",
    "versions": [
      {
        "version": "v2.3.1 to v3.161.1",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "LY Corporation",
    "product": "'Yahoo! JAPAN' App for iOS",
    "versions": [
      {
        "version": "v3.2.2 to v4.109.0",
        "status": "affected"
      }
    ]
  }
]

5.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Related for CVE-2024-28895