SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-13097

Attackers can manipulate users' score parameters exchanged between client and server.

HIGH 7.5EPSS 1.37%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.37%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The application API of Cat Runner Decorate Home version 2.8.0 for Android does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable. Attackers can manipulate users' score parameters exchanged between client and server.

CVSS 3.0
7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
1.37% probability · 70th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
cat runner\/ decorate home project
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.