Vulnerability Description
The Framer Preview application 12 for Android exposes com.framer.viewer.FramerViewActivity to other applications. By calling the intent with the action set to android.intent.action.VIEW, any other application is able to load any website/web content into the application's context, which is shown as a full-screen overlay to the user.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Framer | Framer Preview | 12.0 |
References
- http://packetstormsecurity.com/files/159264/Framer-Preview-12-Content-Injection.ExploitThird Party AdvisoryVDB Entry
- https://rcesecurity.comBroken Link
- http://packetstormsecurity.com/files/159264/Framer-Preview-12-Content-Injection.ExploitThird Party AdvisoryVDB Entry
- https://rcesecurity.comBroken Link
FAQ
What is CVE-2020-25203?
CVE-2020-25203 is a vulnerability with a CVSS score of 5.5 (MEDIUM). The Framer Preview application 12 for Android exposes com.framer.viewer.FramerViewActivity to other applications. By calling the intent with the action set to android.intent.action.VIEW, any other app...
How severe is CVE-2020-25203?
CVE-2020-25203 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-25203?
Check the references section above for vendor advisories and patch information. Affected products include: Framer Framer Preview.