CVE-2019-8792

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
18/12/2019
Last modified:
23/12/2019

Description

An injection issue was addressed with improved validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apple:shazam:9.25.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
cpe:2.3:a:apple:shazam:12.11.0:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*