CVE-2024-49419: Input Validation
Published Dec 3, 2024
·Updated
Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows remote attackers to load an arbitrary URL in its webview.
Affected Software
2 affected components
GamingHub GamingHub<6.1.03.4
GamingHub GamingHub<7.1.02.4
Event History
Dec 3, 2024
CVE Published
via MITRE·05:48 AM
Data Sourced
via MITRE·05:48 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-49419?
CVE-2024-49419 is classified as a high severity vulnerability due to insufficient verification of URL authenticity.
2
How do I fix CVE-2024-49419?
To fix CVE-2024-49419, update GamingHub to version 6.1.03.4 or later for Korea, or 7.1.02.4 or later for Global.
3
What are the potential impacts of CVE-2024-49419?
CVE-2024-49419 allows remote attackers to load arbitrary URLs in the app's webview, risking user data exposure and application misuse.
4
Which versions of GamingHub are affected by CVE-2024-49419?
CVE-2024-49419 affects GamingHub versions prior to 6.1.03.4 in Korea and 7.1.02.4 in Global.
5
Who can exploit CVE-2024-49419?
CVE-2024-49419 can be exploited by remote attackers who can craft a malicious URL.