PT-2024-31481 · Unknown · @Cosme App For Ios+1

Pantuhong Sorasiri

·

Published

2024-09-08

·

Updated

2024-09-16

·

CVE-2024-45203

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions @cosme App for Android versions prior to 5.69.0 @cosme App for iOS versions prior to 6.74.0
Description The issue is related to improper authorization in the handler for the custom URL scheme, which allows an attacker to lead a user to access an arbitrary website via the vulnerable App. This could result in the user becoming a victim of a phishing attack.
Recommendations For @cosme App for Android versions prior to 5.69.0, update to version 5.69.0 or later to resolve the issue. For @cosme App for iOS versions prior to 6.74.0, update to version 6.74.0 or later to resolve the issue. As a temporary workaround, consider restricting access to custom URL schemes in the @cosme App to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-45203

Affected Products

@Cosme App For Android
@Cosme App For Ios