CVE-2019-9140: Happypointcard Happypoint

High severity, CVSS 8.1. EPSS: 1.2% chance of exploitation in the next 30 days.

When processing Deeplink scheme, Happypoint mobile app 6.3.19 and earlier versions doesn't check Deeplink URL correctly. This could lead to javascript code execution, url redirection, sensitive information disclosure. An attacker can exploit this issue by enticing an unsuspecting user to open a specific malicious URL.

Affected products

Published 2019-08-01. Last modified 2026-06-17.