Lucene search

K
jvnJapan Vulnerability NotesJVN:03447226
HistoryAug 24, 2023 - 12:00 a.m.

JVN#03447226: "Skylark" App fails to restrict custom URL schemes properly

2023-08-2400:00:00
Japan Vulnerability Notes
jvn.jp
18
skylark
unauthorized access
custom url schemes
cwe-939
update application
android
ios

4.7 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

0.001 Low

EPSS

Percentile

20.6%

“Skylark” App provided by SKYLARK HOLDINGS CO., LTD. provides the function to access a requested URL using Custom URL Scheme. The App does not restrict access to the function properly (CWE-939) which may be exploited to direct the App to access any sites.

Impact

An arbitrary site may be displayed on the WebView of the product by using another application installed on the user’s device. As a result, the user may be redirected to a malicious site.

Solution

Update the application
Update the application to the latest version according to the information provided by the developer.

Products Affected

  • “Skylark” App for Android versions 6.2.13 and earlier
  • “Skylark” App for iOS versions 6.2.13 and earlier

4.7 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

0.001 Low

EPSS

Percentile

20.6%

Related for JVN:03447226