CVE Vulnerabilities

CVE-2024-45203

Published: Sep 09, 2024 | Modified: Sep 16, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Improper authorization in handler for custom URL scheme issue in @cosme App for Android versions prior 5.69.0 and @cosme App for iOS versions prior to 6.74.0 allows an attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.

Affected Software

Name Vendor Start Version End Version
@cosme Istyle * 5.69.0 (excluding)
@cosme Istyle * 6.74.0 (including)

References