CVE-2022-28799
Last modified
CVE-2022-28799 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The TikTok application before 23.7.3 for Android allows account takeover. A crafted URL (unvalidated deeplink) can force the com.zhiliaoapp.musically WebView to load an arbitrary website. EPSS estimates a 15.53% chance of exploitation in the next 30 days.
Description
The TikTok application before 23.7.3 for Android allows account takeover. A crafted URL (unvalidated deeplink) can force the com.zhiliaoapp.musically WebView to load an arbitrary website. This may allow an attacker to leverage an attached JavaScript interface for the takeover with one click.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tiktok | Tiktok | < 23.7.3 |
References
- https://hackerone.com/reports/1500614Issue Tracking, Third Party Advisory
- https://hackerone.com/reports/1500614Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-28799?
How severe is CVE-2022-28799?
How do I fix CVE-2022-28799?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-28791Improper input validation vulnerability in InstallAgent in G…5.5
- CVE-2022-28792DLL hijacking vulnerability in Gear IconX PC Manager prior t…7.8
- CVE-2022-28793Given the TEE is compromised and controlled by the attacker,…4.4
- CVE-2022-28794Sensitive information exposure in low-battery dumpstate log …3.3
- CVE-2022-28795A vulnerability within the Avira Password Manager Browser Ex…6.5
- CVE-2022-28796jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Li…7
- CVE-2022-2880Requests forwarded by ReverseProxy include the raw query par…7.5
- CVE-2022-28802Code by Zapier before 2022-08-17 allowed intra-account privi…9.9
- CVE-2022-28803In SilverStripe Framework through 2022-04-07, Stored XSS can…5.4
- CVE-2022-28805singlevar in lparser.c in Lua from (including) 5.4.0 up to (…9.1
- CVE-2022-28806An issue was discovered on certain Fujitsu LIEFBOOK devices …7.8
- CVE-2022-28807An issue was discovered in Open Design Alliance Drawings SDK…7.8
Are you affected by CVE-2022-28799?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
