Back to search
CVE-2020-5604
Published: Jul 9, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
Android App 'Mercari' (Japan version) prior to version 3.52.0 allows arbitrary method execution of a Java object by a remote attacker via a Man-In-The-Middle attack by using Java Reflection API of JavaScript code on WebView.
| Vendor | Product | Versions |
|---|---|---|
Mercari, Inc. | Android App 'Mercari' (Japan version) | affected prior to version 3.52.0 |
References
https://jvn.jp/en/jp/JVN93167107/index.html
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now