CVE-2013-2318

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
06/06/2013
Last modified:
11/04/2025

Description

The Content Provider in the MovatwiTouch application before 1.793 and MovatwiTouch Paid application before 1.793 for Android does not properly restrict access to authorization information, which allows attackers to hijack Twitter accounts via a crafted application.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jig:movatwitouch:*:-:*:*:*:android:*:* 1.792 (including)
cpe:2.3:a:jig:movatwitouch_paid:*:-:*:*:*:android:*:* 1.792 (including)