Improper access control in Hot Pepper Gourmet App for Android and Hot Pepper Gourmet App for iOS - CVE-2021-20715

 

Improper access control in Hot Pepper Gourmet App for Android and Hot Pepper Gourmet App for iOS - CVE-2021-20715

Published: April 27, 2021


Vulnerability identifier: #VU52601
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-20715
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. A remote application can receive an request from an arbitrary App and execute access.


Affected software

Hot Pepper Gourmet App for Android
Hot Pepper Gourmet App for iOS

How to mitigate CVE-2021-20715

Install updates from vendor's website.

Hot Pepper Gourmet App for Android - update to 4.111.5
Hot Pepper Gourmet App for iOS - update to 4.111.5

External References

Related Security Bulletins