CVE Vulnerabilities

CVE-2023-42581

Published: Dec 05, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Improper URL validation from InstantPlay deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to access data.

Affected Software

Name Vendor Start Version End Version
Galaxy_store Samsung * 4.5.64.4 (excluding)

References