PT-2013-3648 · Fenrir · Sleipnir Mobile+1
Keita Haga
·
Published
2013-04-16
·
Updated
2013-04-16
·
CVE-2013-2304
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Sleipnir Mobile application versions 2.8.0 and earlier
Sleipnir Mobile Black Edition application versions 2.8.0 and earlier
Description
The issue allows remote attackers to load arbitrary Extension APIs, and trigger downloads or obtain sensitive HTTP response-body information, via a crafted web page.
Recommendations
For Sleipnir Mobile application versions 2.8.0 and earlier, consider restricting access to Extension APIs until a patch is available.
For Sleipnir Mobile Black Edition application versions 2.8.0 and earlier, consider restricting access to Extension APIs until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sleipnir Mobile
Sleipnir Mobile Black Edition