{"api_version":"1","generated_at":"2026-07-23T09:02:12+00:00","cve":"CVE-2019-9140","urls":{"html":"https://cve.report/CVE-2019-9140","api":"https://cve.report/api/cve/CVE-2019-9140.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-9140","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-9140"},"summary":{"title":"CVE-2019-9140","description":"When processing Deeplink scheme, Happypoint mobile app 6.3.19 and earlier versions doesn't check Deeplink URL correctly. This could lead to javascript code execution, url redirection, sensitive information disclosure. An attacker can exploit this issue by enticing an unsuspecting user to open a specific malicious URL.","state":"PUBLIC","assigner":"vuln@krcert.or.kr","published_at":"2019-08-01 17:15:00","updated_at":"2020-10-22 17:19:00"},"problem_types":["CWE-601"],"metrics":[],"references":[{"url":"https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35103","name":"https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35103","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"KrCERT/CC - KISA 인터넷 보호나라&KrCERT","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-9140","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-9140","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"9140","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"happypointcard","cpe5":"happypoint","cpe6":"6.3.19","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"9140","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"happypointcard","cpe5":"happypoint","cpe6":"6.3.19","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"vuln@krcert.or.kr","DATE_PUBLIC":"2019-08-01T04:00:00.000Z","ID":"CVE-2019-9140","STATE":"PUBLIC","TITLE":"Happypoint mobile application information disclosure vulnerability"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Happypoint mobile app","version":{"version_data":[{"platform":"Android","version_affected":"<=","version_name":"6.3.19","version_value":"6.3.19"}]}}]},"vendor_name":"SPC CLOUD"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"When processing Deeplink scheme, Happypoint mobile app 6.3.19 and earlier versions doesn't check Deeplink URL correctly. This could lead to javascript code execution, url redirection, sensitive information disclosure. An attacker can exploit this issue by enticing an unsuspecting user to open a specific malicious URL."}]},"generator":{"engine":"Vulnogram 0.0.7"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.0"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-94 Improper Control of Generation of Code ('Code Injection')"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","url":"https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35103","name":"https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35103"}]},"source":{"discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2019-08-01 17:15:00","lastModifiedDate":"2020-10-22 17:19:00","problem_types":["CWE-601"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":8.1,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.2},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:happypointcard:happypoint:6.3.19:*:*:*:*:android:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"9140","Ordinal":"147001","Title":"CVE-2019-9140","CVE":"CVE-2019-9140","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"9140","Ordinal":"1","NoteData":"When processing Deeplink scheme, Happypoint mobile app 6.3.19 and earlier versions doesn't check Deeplink URL correctly. This could lead to javascript code execution, url redirection, sensitive information disclosure. An attacker can exploit this issue by enticing an unsuspecting user to open a specific malicious URL.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"9140","Ordinal":"2","NoteData":"2019-08-01","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"9140","Ordinal":"3","NoteData":"2019-08-01","Type":"Other","Title":"Modified"}]}}}