PT-2022-7126 · Samsung · Galaxy Store

Ken Gannon

·

Published

2022-12-05

·

Updated

2023-02-17

·

CVE-2023-21434

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Galaxy Store versions prior to 4.5.49.8
Description The issue exists due to inadequate protection of the web page structure, allowing an attacker to execute a JavaScript script when a web page is loaded. This is caused by an improper input validation vulnerability, which enables local attackers to launch a web page and execute JavaScript.
Recommendations For Galaxy Store versions prior to 4.5.49.8, update to version 4.5.49.8 or later to resolve the issue. As a temporary workaround, consider restricting the execution of JavaScript scripts within the Galaxy Store application to minimize the risk of exploitation.

Fix

XSS

RCE

Weakness Enumeration

Related Identifiers

BDU:2023-07686
CVE-2023-21434

Affected Products

Galaxy Store