PT-2022-23679 · Unknown · Waterplugin

Jeremy Chatterson

·

Published

2022-09-09

·

Updated

2023-07-21

·

CVE-2022-36875

CVSS v3.1

6.6

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Waterplugin versions prior to 2.2.11.22081151
Description The issue is related to improper restriction of broadcasting Intent in SaWebViewRelayActivity, allowing an attacker to access files without permission.
Recommendations For versions prior to 2.2.11.22081151, update to version 2.2.11.22081151 or later to resolve the issue.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2022-36875

Affected Products

Waterplugin