VYPR
Medium severity6.1NVD Advisory· Published Mar 18, 2020· Updated Jun 17, 2026

CVE-2019-12366

CVE-2019-12366

Description

The Nine application through 4.5.3a for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Nine/Nine applicationdescription
  • Nine/Ninellm-create
    Range: <=4.5.3a
  • cpe:2.3:a:9folders:nine:*:*:*:*:*:android:*:*
    Range: <=4.5.3a

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.