PT-2020-18593 · Nitori · Nitori App For Android+1
Satoru Nagaoka
·
Published
2020-08-28
·
Updated
2020-09-04
·
CVE-2020-5623
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
NITORI App for Android versions 6.0.4 and earlier
NITORI App for iOS versions 6.0.2 and earlier
Description
The issue allows remote attackers to lead a user to access an arbitrary website via the vulnerable App, potentially resulting in the user becoming a victim of a phishing attack.
Recommendations
For NITORI App for Android versions 6.0.4 and earlier, update to a version later than 6.0.4 to resolve the issue.
For NITORI App for iOS versions 6.0.2 and earlier, update to a version later than 6.0.2 to resolve the issue.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nitori App For Android
Nitori App For Ios