CVE-2023-29459

The laola.redbull application through 5.1.9-R for Android exposes the exported activity at.redbullsalzburg.android.AppMode.Default.Splash.SplashActivity, which accepts a data: URI. The target of this URI is subsequently loaded into the application's webview, thus allowing the loading of arbitrary content into the context of the application. This can occur via the fcrbs schema or an explicit intent invocation.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redbull:fc_red_bull_salzburg:*:*:*:*:*:android:*:*

History

No history.

Information

Published : 2023-06-26 16:15

Updated : 2024-12-03 20:15


NVD link : CVE-2023-29459

Mitre link : CVE-2023-29459

CVE.ORG link : CVE-2023-29459


JSON object : View

Products Affected

redbull

  • fc_red_bull_salzburg
CWE
NVD-CWE-Other CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')