CVE-2023-21434: XSS
Published Feb 9, 2023
·Updated
Improper input validation vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to execute JavaScript by launching a web page.
Affected Software
1 affected component
Samsung Galaxy Store<4.5.49.8
Event History
Feb 9, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-21434 vulnerability?
CVE-2023-21434 is an improper input validation vulnerability in Galaxy Store prior to version 4.5.49.8 that allows local attackers to execute JavaScript by launching a web page.
2
How severe is CVE-2023-21434 vulnerability?
CVE-2023-21434 vulnerability has a severity value of 6.1, classified as medium.
3
What software is affected by CVE-2023-21434?
Samsung Galaxy Store versions up to exclusive 4.5.49.8 are affected by CVE-2023-21434.
4
Can local attackers execute JavaScript through CVE-2023-21434?
Yes, local attackers can execute JavaScript by launching a web page due to CVE-2023-21434 vulnerability.