Vulnerability Description
The Content Provider in the MovatwiTouch application before 1.793 and MovatwiTouch Paid application before 1.793 for Android does not properly restrict access to authorization information, which allows attackers to hijack Twitter accounts via a crafted application.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jig | Movatwitouch | <= 1.792 |
| Jig | Movatwitouch Paid | <= 1.792 |
Related Weaknesses (CWE)
References
- http://jvn.jp/en/jp/JVN90289505/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2013-000047
- http://movatwitter.jugem.jp/?eid=442
- http://jvn.jp/en/jp/JVN90289505/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2013-000047
- http://movatwitter.jugem.jp/?eid=442
FAQ
What is CVE-2013-2318?
CVE-2013-2318 is a vulnerability with a CVSS score of 2.6 (LOW). The Content Provider in the MovatwiTouch application before 1.793 and MovatwiTouch Paid application before 1.793 for Android does not properly restrict access to authorization information, which allow...
How severe is CVE-2013-2318?
CVE-2013-2318 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-2318?
Check the references section above for vendor advisories and patch information. Affected products include: Jig Movatwitouch, Jig Movatwitouch Paid.