CVE-2019-8791

Severity CVSS v4.0:
Pending analysis
Type:
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
18/12/2019
Last modified:
02/01/2020

Description

An issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to an open redirect.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apple:shazam:*:*:*:*:*:iphone_os:*:* 9.25.0 (excluding)
cpe:2.3:a:apple:shazam:*:*:*:*:*:android:*:* 12.11.0 (excluding)