PT-2013-5758 · Tapbots · Tweetbot

Guillaume Ross

·

Published

2013-11-12

·

Updated

2013-11-13

·

CVE-2013-5726

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Tweetbot versions 1.3.3 for Mac, and 2.8.5 for iPad and iPhone
Description The issue allows remote attackers to automatically force the user to perform undesired actions, such as follow or favorite actions, without confirmation. This can be achieved via the "tweetbot:///follow/" URL.
Recommendations For Tweetbot version 1.3.3 on Mac, consider disabling the ability to perform follow or favorite actions via URLs until a patch is available. For Tweetbot version 2.8.5 on iPad and iPhone, restrict access to the tweetbot:///follow/ URL to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-5726

Affected Products

Tweetbot