Description
Android App 'Mercari' (Japan version) prior to version 3.52.0 allows arbitrary method execution of a Java object by a remote attacker via a Man-In-The-Middle attack by using Java Reflection API of JavaScript code on WebView.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-26765 | Android App 'Mercari' (Japan version) prior to version 3.52.0 allows arbitrary method execution of a Java object by a remote attacker via a Man-In-The-Middle attack by using Java Reflection API of JavaScript code on WebView. |
References
| Link | Providers |
|---|---|
| https://jvn.jp/en/jp/JVN93167107/index.html |
|
History
No history.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-08-04T08:30:24.580Z
Reserved: 2020-01-06T00:00:00.000Z
Link: CVE-2020-5604
No data.
Status : Modified
Published: 2020-07-09T02:15:10.527
Modified: 2024-11-21T05:34:20.907
Link: CVE-2020-5604
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD