Vulnerabilities (CVE)

Filtered by vendor Sap Subscribe
Filtered by product Emarsys Sdk
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-6542 1 Sap 1 Emarsys Sdk 2023-12-18 N/A 7.1 HIGH
Due to lack of proper authorization checks in Emarsys SDK for Android, an attacker can call a particular activity and can forward himself web pages and/or deep links without any validation directly from the host application. On successful attack, an attacker could navigate to arbitrary URL including application deep links on the device.