apps.apple.com
https://apps.apple.com/jp/app/%E3%81%99%E3%81%8B%E3%81%84%E3%82%89%E3%83%BC%E3%81%8F%E3%82%A2%E3%83%97%E3%83%AA/id906930478 CVE-2024-54014
LOW
Record summary
CVE-2024-54014 has a selected CVSS score of 3.6 (low).
Description
Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skylark' App for iOS 6.2.13 and earlier allows an attacker to lead the application to access an arbitrary web site via another application installed on the user's device.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 5, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
'Skylark' App for AndroidBrowse SKYLARK HOLDINGS CO., LTD. / 'Skylark' App for Android | CVE List | 6.2.13 and earlier | affected |
'Skylark' App for iOSBrowse SKYLARK HOLDINGS CO., LTD. / 'Skylark' App for iOS | CVE List | 6.2.13 and earlier | affected |
References
4jvn.jp
https://jvn.jp/en/jp/JVN03447226 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-54014 play.google.com
https://play.google.com/store/apps/details?id=jp.co.skylark.app.gusto