CVE-2019-9140

Publication date

2019-08-01 16:54:17

Family

krcert

State

PUBLISHED

Description

When processing Deeplink scheme, Happypoint mobile app 6.3.19 and earlier versions doesnt check Deeplink URL correctly. This could lead to javascript code execution, url redirection, sensitive information disclosure. An attacker can exploit this issue by enticing an unsuspecting user to open a specific malicious URL.