CVE Vulnerabilities

CVE-2023-21515

Published: May 26, 2023 | Modified: Jun 03, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.

Affected Software

Name Vendor Start Version End Version
Galaxy_store Samsung * 4.5.49.8 (excluding)

References