Portuguese security researcher David Sopas has identified a couple of vulnerabilities in RunKeeper, the highly popular fitness-tracking application.
According to the expert, the security holes a cross-site scripting (XSS) and a cross-site reference forgery (CSRF) could have been exploited by cybercriminals to run an XSS worm.
The CSRF issue impacted the Account Settings section.
Using an external HTML form, a crafted site with an a…