CVE-2020-25203
Summary
| CVE | CVE-2020-25203 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-25 04:23:00 UTC |
| Updated | 2020-10-06 19:58:00 UTC |
| Description | The Framer Preview application 12 for Android exposes com.framer.viewer.FramerViewActivity to other applications. By calling the intent with the action set to android.intent.action.VIEW, any other application is able to load any website/web content into the application's context, which is shown as a full-screen overlay to the user. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Framer | Framer Preview | 12.0 | All | All | All |
| Application | Framer | Framer Preview | 12.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| RCE Security – Remote Code Execution Techniques and more | MISC | rcesecurity.com | Broken Link |
| Framer Preview 12 Content Injection ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.