Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-41372 | Improper authorization in handler for custom URL scheme issue in "@cosme" App for Android versions prior 5.69.0 and "@cosme" App for iOS versions prior to 6.74.0 allows an attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack. |
| Link | Providers |
|---|---|
| https://jvn.jp/en/jp/JVN81570776/ |
|
Thu, 13 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-939 |
Mon, 16 Sep 2024 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Istyle
Istyle \@cosme |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:istyle:\@cosme:*:*:*:*:*:android:*:* cpe:2.3:a:istyle:\@cosme:*:*:*:*:*:iphone_os:*:* |
|
| Vendors & Products |
Istyle
Istyle \@cosme |
|
| Metrics |
cvssV3_1
|
Mon, 09 Sep 2024 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Sep 2024 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper authorization in handler for custom URL scheme issue in "@cosme" App for Android versions prior 5.69.0 and "@cosme" App for iOS versions prior to 6.74.0 allows an attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack. | |
| References |
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2025-03-13T19:35:38.439Z
Reserved: 2024-08-23T00:35:41.010Z
Link: CVE-2024-45203
Updated: 2024-09-09T13:08:48.922Z
Status : Modified
Published: 2024-09-09T07:15:17.030
Modified: 2025-03-13T20:15:22.630
Link: CVE-2024-45203
No data.
OpenCVE Enrichment
No data.
EUVD