Vulnerability Description
An intent redirection issue was doscovered in Sina Weibo Android SDK 4.2.7 (com.sina.weibo.sdk.share.WbShareTransActivity), any unexported Activities could be started by the com.sina.weibo.sdk.share.WbShareTransActivity.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Android Software Development Kit | 4.2.7 |
References
- https://github.com/sinaweibosdk/weibo_android_sdk/issues/406ExploitIssue TrackingThird Party Advisory
- https://github.com/sinaweibosdk/weibo_android_sdk/issues/406ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2020-23349?
CVE-2020-23349 is a vulnerability with a CVSS score of 7.5 (HIGH). An intent redirection issue was doscovered in Sina Weibo Android SDK 4.2.7 (com.sina.weibo.sdk.share.WbShareTransActivity), any unexported Activities could be started by the com.sina.weibo.sdk.share.W...
How severe is CVE-2020-23349?
CVE-2020-23349 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-23349?
Check the references section above for vendor advisories and patch information. Affected products include: Weibo Android Software Development Kit.