Improper authorization in handler for custom URL scheme vulnerability in あすけんダイエット (asken diet) for Android versions from v.3.0.0 to v.4.2.x allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://www.asken.jp/s/login/?to=/information | vendor advisory permissions required |
https://jvn.jp/en/jp/JVN38034268/index.html | third party advisory |