Xavier can inject scripts into the web view because it allows embedding content using deep linking without proper authorization and validation of the host, schema and path of the target as these can be changed by the user or because safe browsing is disabled
Xavier can inject scripts into the web view because it allows embedding content using deep linking without proper authorization and validation of the host, schema and path of the target as these can be changed by the user or because safe browsing is disabled
OWASP ASVS
PLATFORM-1,PLATFORM-2
OWASP AppSensor
TEST-0027,TEST-0028,TEST-0031,TEST-0070,TEST-0076,TEST-0077
CAPEC
-
SAFECODE
OWASP MASVS (2.1): PLATFORM-1 ,PLATFORM-2
OWASP MASTG (1.7): TEST-0027 ,TEST-0028 ,TEST-0031 ,TEST-0070 ,TEST-0076 ,TEST-0077
Capec: 175 ,240 ,242 ,500 ,591 ,592
Safecode: 17
No attacks registered!