Due to lack of proper authorization checks in Emarsys SDK for Android, an attacker can call a particular activity and can forward himself web pages and/or deep links without any validation directly from the host application. On successful attack, an attacker could navigate to arbitrary URL including application deep links on the device.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: sap
Published: 2023-12-12T01:36:22.773Z
Updated: 2024-08-02T08:35:13.594Z
Reserved: 2023-12-06T03:42:15.409Z
Link: CVE-2023-6542
No data.
Status : Modified
Published: 2023-12-12T02:15:09.347
Modified: 2024-11-21T08:44:03.740
Link: CVE-2023-6542
No data.