Insufficient URL Restrictions in MinigameCenter Module by Vivo
CVE-2024-13185

6.3MEDIUM

Key Information:

Vendor
Vivo
Status
Minigamecenter
Vendor
CVE Published:
8 January 2025

Summary

The MinigameCenter module from Vivo suffers from a flaw that allows for insufficient restrictions during URL loading. This vulnerability can potentially result in information leakage, posing a risk to user data and privacy. Organizations using this module should assess their exposure and consider implementing mitigations to protect sensitive information.

Affected Version(s)

MinigameCenter Versions below 2.3.5.0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.