PT-2013-5758 · Tapbots · Tweetbot
Guillaume Ross
·
Published
2013-11-12
·
Updated
2013-11-13
·
CVE-2013-5726
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Tweetbot versions 1.3.3 for Mac, and 2.8.5 for iPad and iPhone
Description
The issue allows remote attackers to automatically force the user to perform undesired actions, such as follow or favorite actions, without confirmation. This can be achieved via the "tweetbot:///follow/" URL.
Recommendations
For Tweetbot version 1.3.3 on Mac, consider disabling the ability to perform follow or favorite actions via URLs until a patch is available.
For Tweetbot version 2.8.5 on iPad and iPhone, restrict access to the tweetbot:///follow/ URL to minimize the risk of exploitation.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tweetbot