CVE-2019-12366: XSS
The Nine application through 4.5.3a for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READEXTERNALSTORAGE permission.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-12366?
CVE-2019-12366 is a vulnerability found in the Nine application for Android that allows XSS (Cross-Site Scripting) attacks and arbitrary file loading.
What is the severity of CVE-2019-12366?
CVE-2019-12366 has a severity rating of 6.1 (Medium).
How does CVE-2019-12366 affect the Nine application?
CVE-2019-12366 affects the Nine application through version 4.5.3a on Android by allowing XSS attacks via an event attribute and arbitrary file loading via a src attribute.
What permissions does the Nine application need for CVE-2019-12366 to be exploited?
To exploit CVE-2019-12366 in the Nine application, the application needs to have the READ_EXTERNAL_STORAGE permission.
How can I fix CVE-2019-12366?
To fix CVE-2019-12366, it is recommended to update the Nine application to a version that has addressed the vulnerability.