The Content Provider in the MovatwiTouch application before 1.793 and MovatwiTouch Paid application before 1.793 for Android does not properly restrict access to authorization information, which allows attackers to hijack Twitter accounts via a crafted application.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2013-06-06 06:02
Updated : 2013-06-06 21:00
NVD link : CVE-2013-2318
Mitre link : CVE-2013-2318
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
jig
- movatwitouch_paid
- movatwitouch