When processing Deeplink scheme, Happypoint mobile app 6.3.19 and earlier versions doesn't check Deeplink URL correctly. This could lead to javascript code execution, url redirection, sensitive information disclosure. An attacker can exploit this issue by enticing an unsuspecting user to open a specific malicious URL.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35103 | Third Party Advisory | 
Configurations
                    Information
                Published : 2019-08-01 10:15
Updated : 2020-10-22 10:19
NVD link : CVE-2019-9140
Mitre link : CVE-2019-9140
JSON object : View
CWE
                
                    
                        
                        CWE-601
                        
            URL Redirection to Untrusted Site ('Open Redirect')
Products Affected
                happypointcard
- happypoint
 


