PT-2024-26422 · Unknown · Zozotown App For Android

Published

2024-06-19

·

Updated

2024-07-03

·

CVE-2024-35298

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions ZOZOTOWN App for Android versions prior to 7.39.6
Description The issue is related to improper authorization in the handler for a custom URL scheme, which allows an attacker to lead a user to access an arbitrary website via another application installed on the user's device. This could result in the user becoming a victim of a phishing attack.
Recommendations For ZOZOTOWN App for Android versions prior to 7.39.6, update to version 7.39.6 or later to resolve the issue. As a temporary workaround, consider restricting the use of custom URL schemes in the app to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-35298

Affected Products

Zozotown App For Android