CVE-2019-13097
Summary
| CVE | CVE-2019-13097 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-22 17:15:00 UTC |
| Updated | 2019-07-26 14:25:00 UTC |
| Description | The application API of Cat Runner Decorate Home version 2.8.0 for Android does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable. Attackers can manipulate users' score parameters exchanged between client and server. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cat Runner | Decorate Home Project | cat_runner | _decorate_home | 2.8.0 | All |
| Application | Cat Runner | Decorate Home Project | cat_runner\ | _decorate_home | 2.8.0 | All |
| Application | Cat Runner | Decorate Home Project | cat_runner\ | _decorate_home | 2.8.0 | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CatRunner - Pastebin.com | MISC | pastebin.com | Exploit, Third Party Advisory |
| YouTube | MISC | www.youtube.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.