CVE-2019-13097
Last modified
CVE-2019-13097 is a vulnerability of currently unknown severity. The application API of Cat Runner Decorate Home version 2.8.0 for Android does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable. Attackers can manipulate users' score parameters exchanged between client and server.. EPSS estimates a 1.37% chance of exploitation in the next 30 days.
Description
The application API of Cat Runner Decorate Home version 2.8.0 for Android does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable. Attackers can manipulate users' score parameters exchanged between client and server.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Cat Runner\ | Decorate Home Project | cat_runner\ | Decorate Home |
References
- https://pastebin.com/WkkGk0twExploit, Third Party Advisory
- https://www.youtube.com/watch?v=u5iEeLZnYVgExploit, Third Party Advisory
- https://pastebin.com/WkkGk0twExploit, Third Party Advisory
- https://www.youtube.com/watch?v=u5iEeLZnYVgExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-13097?
How severe is CVE-2019-13097?
How do I fix CVE-2019-13097?
Are you affected by CVE-2019-13097?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
