CVE-2020-5604

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/07/2020
Last modified:
21/07/2021

Description

Android App 'Mercari' (Japan version) prior to version 3.52.0 allows arbitrary method execution of a Java object by a remote attacker via a Man-In-The-Middle attack by using Java Reflection API of JavaScript code on WebView.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mercari:mercari:*:*:*:*:*:android:*:* 3.52.0 (excluding)


References to Advisories, Solutions, and Tools