RushBet 2022.23.1-b490616d - Universal XSS
6
Medium
Discovered by

Offensive Team, Fluid Attacks
Summary
Full name
RushBet 2022.23.1-b490616d - UXSS
Code name
State
Public
Release date
10 ene 2023
Affected product
RushBet
Affected version(s)
Version 2022.23.1-b490616d
Vulnerability name
Universal XSS
Vulnerability type
Remotely exploitable
Yes
CVSS v3.1 vector string
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
CVSS v3.1 base score
6.0
Exploit available
Yes
CVE ID(s)
Description
RushBet version 2022.23.1-b490616d allows a remote attacker to steal customer accounts via use of a malicious application. This is possible because the application exposes an activity and does not properly validate the data it receives.
Vulnerability
This vulnerability occurs because the application exposes an activity and does not properly validate the data it receives.
Exploitation
To exploit this vulnerability, the victim must have a malicious application installed with activity like the following:
MainActivity.java
Thus, when the victim opens the malicious app, the exploit will be executed, thus hacking his account.
Evidence of exploitation

Our security policy
We have reserved the CVE-2022-4235 to refer to this issue from now on. Disclosure policy
System Information
Version: RushBet 2022.23.1-b490616d
Operating System: GNU/Linux
Mitigation
An updated version of RushBet is available at the vendor page.
References
Vendor page https://www.rushbet.co
Timeline
IA generativa
29 nov 2022
Vendor Confirmed Vuln.
3 dic 2022
Vulnerability patched
14 dic 2022
Vendor contacted
30 nov 2022
Vendor replied
3 dic 2022
Public disclosure
10 ene 2023