Vulnérabilité · NVD
CVE-2022-28799
CVE-2022-28799, sévérité high (CVSS 8.8) : 1 app suivie concernée, toutes corrigées ou à statut indéterminable en version courante.
- Gravité (CVSS)
- 8.8
- Exploitation
- 16.0 %
- Apps suivies
- 1
- Encore exposées
- 0
Échelle NVD
EPSS, prédiction à 30 jours
EN The TikTok application before 23.7.3 for Android allows account takeover. A crafted URL (unvalidated deeplink) can force the com.zhiliaoapp.musically WebView to load an arbitrary website. This may allow an attacker to leverage an attached JavaScript interface for the takeover with one click.
Vecteur d'attaque : Réseau
Aucun privilège requis
Voir le vecteur CVSS brut
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
16.03%
exploit modéré
percentile 96.8%
Apps suivies liées à cette CVE
Pour chaque app : la plage affectée, la version qui corrige, et où en est l'app suivie aujourd'hui.
Configurations CPE vulnérables (1)
| Vendor | Produit | Plateforme | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| tiktok |
tiktok Android
|
Android | <23.7.3 | cpe:2.3:a:tiktok:tiktok:*:*:*:*:*:android:*:* |