Vulnerability Description
RushBet version 2022.23.1-b490616d allows a remote attacker to steal customer accounts via use of a malicious application. This is possible because the application exposes an activity and does not properly validate the data it receives.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rushstreetinteractive | Rushbet | 2022.23.1-b490616d |
Related Weaknesses (CWE)
References
- https://fluidattacks.com/advisories/miller/ExploitThird Party Advisory
- https://fluidattacks.com/advisories/miller/ExploitThird Party Advisory
FAQ
What is CVE-2022-4235?
CVE-2022-4235 is a vulnerability with a CVSS score of 5.4 (MEDIUM). RushBet version 2022.23.1-b490616d allows a remote attacker to steal customer accounts via use of a malicious application. This is possible because the application exposes an activity and does not pro...
How severe is CVE-2022-4235?
CVE-2022-4235 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-4235?
Check the references section above for vendor advisories and patch information. Affected products include: Rushstreetinteractive Rushbet.