CVE-2019-9140
Last modified
CVE-2019-9140 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. When processing Deeplink scheme, Happypoint mobile app 6.3.19 and earlier versions doesn't check Deeplink URL correctly. This could lead to javascript code execution, url redirection, sensitive information disclosure. EPSS estimates a 1.19% chance of exploitation in the next 30 days.
Description
When processing Deeplink scheme, Happypoint mobile app 6.3.19 and earlier versions doesn't check Deeplink URL correctly. This could lead to javascript code execution, url redirection, sensitive information disclosure. An attacker can exploit this issue by enticing an unsuspecting user to open a specific malicious URL.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Happypointcard | Happypoint | 6.3.19 |
References
- https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35103Third Party Advisory
- https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35103Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-9140?
How severe is CVE-2019-9140?
How do I fix CVE-2019-9140?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-9134Architectural Information System 1.0 and earlier versions ha…9.8
- CVE-2019-9135DaviewIndy 8.98.7 and earlier versions have a Heap-based ove…7.8
- CVE-2019-9136DaviewIndy 8.98.7 and earlier versions have a Heap-based ove…7.8
- CVE-2019-9137DaviewIndy 8.98.7 and earlier versions have a Integer overfl…7.8
- CVE-2019-9138DaviewIndy 8.98.7 and earlier versions have a Integer overfl…7.8
- CVE-2019-9139DaviewIndy 8.98.7 and earlier versions have a Integer overfl…7.8
- CVE-2019-9141ZInsVX.dll ActiveX Control 2018.02 and earlier in Zoneplayer…9.8
- CVE-2019-9142An issue was discovered in b3log Symphony (aka Sym) before v…
- CVE-2019-9143An issue was discovered in Exiv2 0.27. There is infinite rec…
- CVE-2019-9144An issue was discovered in Exiv2 0.27. There is infinite rec…
- CVE-2019-9145An issue was discovered in Hsycms V1.1. There is an XSS vuln…
- CVE-2019-9146Jamf Self Service 10.9.0 allows man-in-the-middle attackers …
Are you affected by CVE-2019-9140?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
