Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-phfm-7q7g-rf2x

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Tweetbot 1.3.3 for Mac, and 2.8.5 for iPad and iPhone, does not require confirmation of (1) follow or (2) favorite actions, which allows remote attackers to automatically force the user to perform undesired actions, as demonstrated via the tweetbot:///follow/ URL.

Tweetbot 1.3.3 for Mac, and 2.8.5 for iPad and iPhone, does not require confirmation of (1) follow or (2) favorite actions, which allows remote attackers to automatically force the user to perform undesired actions, as demonstrated via the tweetbot:///follow/ URL.

EPSS

Процентиль: 52%
0.00292
Низкий

Дефекты

CWE-352

Связанные уязвимости

nvd
около 12 лет назад

Tweetbot 1.3.3 for Mac, and 2.8.5 for iPad and iPhone, does not require confirmation of (1) follow or (2) favorite actions, which allows remote attackers to automatically force the user to perform undesired actions, as demonstrated via the tweetbot:///follow/ URL.

EPSS

Процентиль: 52%
0.00292
Низкий

Дефекты

CWE-352