CVE-2021-25499

CWE-2853 documents3 sources
Severity
5.5MEDIUM
EPSS
0.1%
top 84.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 6
Latest updateMay 24

Description

Intent redirection vulnerability in SamsungAccountSDKSigninActivity of Galaxy Store prior to version 4.5.32.4 allows attacker to access content provider of Galaxy Store.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 1.8 | Impact: 5.2

Affected Packages2 packages

NVDsamsung/galaxy_store< 4.5.32.4
CVEListV5samsung_mobile/galaxy_store-4.5.32.4

🔴Vulnerability Details

2
GHSA
GHSA-2qph-f4rc-vg2c: Intent redirection vulnerability in SamsungAccountSDKSigninActivity of Galaxy Store prior to version 42022-05-24
CVEList
CVE-2021-25499: Intent redirection vulnerability in SamsungAccountSDKSigninActivity of Galaxy Store prior to version 42021-10-06
CVE-2021-25499 (MEDIUM CVSS 5.5) | Intent redirection vulnerability in | cvebase.io