Published: 2015/09/16  Last Updated: 2015/09/16

Information from Newphoria Corporation

Vulnerability ID:JVN#24517322
Title:Koritore vulnerable to URL whitelist bypass
Status:Vulnerable

This is a statement from the vendor itself with no modification by JPCERT/CC.

[Summary]
Vulnerability in access restriction of こりトレ has been found.

[Affected applications]
iOS and Android こりトレapplication up to version 1.0

[Detailed information]
こりトレcould be loaded using URL scheme with the possibility to open an arbitrary page.

[Supposed effect]
A possibility to falsify a file which can be accessed to by an application by the malicious third party.

[Resolution method]
Android
Update from GooglePlay to version 1.1.

iOS
Update from AppStore to version 1.1.


[Acknowledgements]
This vulnerability report was sent according to Information Security Early Warning partnership within regulation between our company and IPA with JPCERT/CC.
The information regarding the vulnerability was reported to us by Sprout Inc.
Our special thanks to Kenta Suefusa and Tomonori Shiomi of Sprout Inc., and also to anyone involved into Information Security Early Warning partnership.