The GREE+ (aka com.gree.greeplus) application 1.4.0.8 for Android suffers from Cross Site Request Forgery.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://medium.com/%40beefaaubee/dissecting-into-gree-android-application-43892d54b006 | |
https://play.google.com/store/apps/details?id=com.gree.greeplus | third party advisory product |