PT-2023-32690 · Emarsys · Emarsys Sdk For Android
Published
2022-02-01
·
Updated
2025-10-31
·
CVE-2023-6542
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SAP Emarsys SDK for Android (affected versions not specified)
Description
The issue is due to a lack of proper authorization checks in the Emarsys SDK for Android, allowing an attacker to call a particular activity and forward web pages and/or deep links without validation directly from the host application. On a successful attack, an attacker could navigate to an arbitrary URL, including application deep links on the device. This could potentially lead to sensitive data leaks from an app's private data directory and allow loading remote contents into an app overlay.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emarsys Sdk For Android