Arbitrary Webpage Loading Vulnerability in SmartThings

Arbitrary Webpage Loading Vulnerability in SmartThings

CVE-2021-25446 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause arbitrary webpage loading in webview.

Learn more about our Web App Pen Testing.