Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2024-41918 Details

Description

'Rakuten Ichiba App' for Android 12.4.0 and earlier and 'Rakuten Ichiba App' for iOS 11.7.0 and earlier are vulnerable to improper authorization in handler for custom URL scheme. An arbitrary site may be displayed on the WebView of the product via Intent from another application installed on the user's device. As a result, the user may be redirected to an unauthorized site, and the user may become a victim of a phishing attack.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-862Missing Authorization[email protected]
CWE-939Improper Authorization in Handler for Custom URL SchemeCISA-ADP

Affected Products

ProductVersions
rakuten ichiba
<= 11.7.0
<= 12.4.0

CPE

  • cpe:2.3:a:rakuten:ichiba:*:*:*:*:*:iphone_os:*:*
  • cpe:2.3:a:rakuten:ichiba:*:*:*:*:*:android:*:*

Remediation

  • No remediation found in references.

Change History

6 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2024-41918
NVD Published Date:
Aug 29, 2024
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]