VulnerabilityModified
CVE-2019-13097
Attackers can manipulate users' score parameters exchanged between client and server.
HIGH 7.5EPSS 1.37%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.37%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The application API of Cat Runner Decorate Home version 2.8.0 for Android does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable. Attackers can manipulate users' score parameters exchanged between client and server.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.37% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- cat runner\/ decorate home project
- Source
- cve@mitre.org
References
- https://pastebin.com/WkkGk0twExploit, Third Party Advisory
- https://www.youtube.com/watch?v=u5iEeLZnYVgExploit, Third Party Advisory
- https://pastebin.com/WkkGk0twExploit, Third Party Advisory
- https://www.youtube.com/watch?v=u5iEeLZnYVgExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.