An issue found in Marukyu Line v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp function.
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Link | Tags |
---|---|
http://marukyu.com | product |
https://github.com/syz913/CVE-reports/blob/main/CVE-2023-31818.md | third party advisory exploit |