First published: Tue Oct 24 2023(Updated: )
The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linecorp Fukunaga Memberscard | =13.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39736 is a vulnerability in Fukunaga_memberscard Line 13.6.1 that allows attackers to obtain the channel access token and send crafted broadcast messages.
The severity level of CVE-2023-39736 is high, with a CVSS score of 8.2.
Attackers can exploit CVE-2023-39736 to obtain the client secret and channel access token, allowing them to send crafted broadcast messages.
To fix CVE-2023-39736, it is recommended to upgrade to a secure version of Fukunaga_memberscard Line, such as version 13.6.2 or later, which addresses the vulnerability.
More information about CVE-2023-39736 can be found in the following references: [CVE-2023-39736 on GitHub](https://github.com/syz913/CVE-reports/blob/main/CVE-2023-39736.md) and [Fukunaga_memberscard Line on LIFF](https://liff.line.me/1657606123-4Kp0xVrP).