CVE-2023-43301
CVSS 3.1 Score 8.2 of 10 (high)
Details
Published Dec 7, 2023
Updated: Dec 13, 2023
CWE ID 94
Summary
CVE-2023-43301 is a vulnerability affecting the DARTS SHOP MAXIM mini-app on Line version 13.6.1. This issue enables attackers to manipulate notifications by exploiting the leakage of channel access tokens. As a result, malicious notifications can be sent to unsuspecting users, potentially leading to privacy breaches or the execution of malicious code. This vulnerability poses a significant risk to Line users interacting with the affected mini-app and emphasizes the importance of securing access tokens to protect against unauthorized access and manipulation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Linecorp