← Back

CVE-2013-5726

nvd nist
Published: Nov 12, 2013Modified: Apr 29, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Tweetbot 1.3.3 for Mac, and 2.8.5 for iPad and iPhone, does not require confirmation of (1) follow or (2) favorite actions, which allows remote attackers to automatically force the user to perform undesired actions, as demonstrated via the tweetbot:///follow/ URL.

Affected (3)

Products: Tapbots: Tweetbot
1 product
Tweetbot
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Tapbots
Version 1.3.3
Version 2.8.5
Version 2.8.5

References (6)

Timeline

No history available yet.