Improper Authorization in e-Gov Client Application by Shinsei
CVE-2023-44689

4.3MEDIUM

What is CVE-2023-44689?

The e-Gov Client Application for Windows and macOS versions prior to 2.1.1.0 and 1.1.1.0 respectively are susceptible to improper authorization through a handler for custom URL schemes. A maliciously crafted URL can potentially redirect the application to access arbitrary websites, posing a significant risk of phishing attacks on users. This vulnerability highlights the need for rigorous URL validation to shield users from social engineering threats.

Affected Version(s)

e-Gov Client Application (macOS version) versions prior to 1.1.1.0

e-Gov Client Application (Windows version) versions prior to 2.1.1.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.