Insufficient URL Restrictions in MinigameCenter Module by Vivo
CVE-2024-13185
6.3MEDIUM
Key Information:
- Vendor
- Vivo
- Status
- Minigamecenter
- Vendor
- CVE Published:
- 8 January 2025
Summary
The MinigameCenter module from Vivo suffers from a flaw that allows for insufficient restrictions during URL loading. This vulnerability can potentially result in information leakage, posing a risk to user data and privacy. Organizations using this module should assess their exposure and consider implementing mitigations to protect sensitive information.
Affected Version(s)
MinigameCenter Versions below 2.3.5.0
References
CVSS V4
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved