First published: Wed Mar 18 2020(Updated: )
The Nine application through 4.5.3a for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
9folders Nine | <=4.5.3a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12366 is a vulnerability found in the Nine application for Android that allows XSS (Cross-Site Scripting) attacks and arbitrary file loading.
CVE-2019-12366 has a severity rating of 6.1 (Medium).
CVE-2019-12366 affects the Nine application through version 4.5.3a on Android by allowing XSS attacks via an event attribute and arbitrary file loading via a src attribute.
To exploit CVE-2019-12366 in the Nine application, the application needs to have the READ_EXTERNAL_STORAGE permission.
To fix CVE-2019-12366, it is recommended to update the Nine application to a version that has addressed the vulnerability.