CVE-2019-16681
Last modified
CVE-2019-16681 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. The Traveloka application 3.14.0 for Android exports com.traveloka.android.activity.common.WebViewActivity, leading to the opening of arbitrary URLs, which can inject deceptive content into the UI. (When in physical possession of the device, opening local files is also possible.) NOTE: As of 2019-09-23, the vendor has not agreed that this issue has serious impact. EPSS estimates a 0.70% chance of exploitation in the next 30 days.
Description
The Traveloka application 3.14.0 for Android exports com.traveloka.android.activity.common.WebViewActivity, leading to the opening of arbitrary URLs, which can inject deceptive content into the UI. (When in physical possession of the device, opening local files is also possible.) NOTE: As of 2019-09-23, the vendor has not agreed that this issue has serious impact. The vendor states that the issue is not critical because it does not allow Elevation of Privilege, Sensitive Data Leakage, or any critical unauthorized activity from a malicious user. The vendor also states that a victim must first install a malicious APK to their application.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Traveloka | Traveloka | 3.14.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-16681?
How severe is CVE-2019-16681?
How do I fix CVE-2019-16681?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-16676Plataformatec Simple Form has Incorrect Access Control in fi…9.8
- CVE-2019-16677An issue was discovered in idreamsoft iCMS V7.0. admincp.php…6.5
- CVE-2019-16678admin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resu…6.5
- CVE-2019-16679Gila CMS before 1.11.1 allows admin/fm/?f=../ directory trav…4.9
- CVE-2019-1668A vulnerability in the chat feed feature of Cisco SocialMine…6.1
- CVE-2019-16680An issue was discovered in GNOME file-roller before 3.29.91.…4.3
- CVE-2019-16682The url_redirect (aka URL redirect) extension through 1.2.1 …7.3
- CVE-2019-16683An issue was discovered in the image-manager in Xoops 2.5.10…4.8
- CVE-2019-16684An issue was discovered in the image-manager in Xoops 2.5.10…4.8
- CVE-2019-16685Dolibarr 9.0.5 has stored XSS vulnerability via a User Group…5.4
- CVE-2019-16686Dolibarr 9.0.5 has stored XSS in a User Note section to note…5.4
- CVE-2019-16687Dolibarr 9.0.5 has stored XSS in a User Profile in a Signatu…5.4
Are you affected by CVE-2019-16681?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
