Confused Deputy Vulnerability in SaveUi.java Allows Unauthorized Access to User Images

Confused Deputy Vulnerability in SaveUi.java Allows Unauthorized Access to User Images

CVE-2023-40122 · Severity

In applyCustomDescription of SaveUi.java, there is a possible way to view other user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Learn more about our User Device Pen Test.