Vulnerability Name: | CVE-2019-8762 (CCN-170273) | ||||||||||||
Assigned: | 2019-07-23 | ||||||||||||
Published: | 2019-07-23 | ||||||||||||
Updated: | 2020-10-30 | ||||||||||||
Summary: | A validation issue was addressed with improved logic. This issue is fixed in Safari 13.0.1, iOS 13.1 and iPadOS 13.1, iCloud for Windows 10.7, tvOS 13, iCloud for Windows 7.14, iTunes 12.10.1 for Windows. Processing maliciously crafted web content may lead to universal cross site scripting. | ||||||||||||
CVSS v3 Severity: | 6.1 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) 5.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
5.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
| ||||||||||||
Vulnerability Type: | CWE-79 | ||||||||||||
Vulnerability Consequences: | Cross-Site Scripting | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-8762 Source: CCN Type: Google Security Research Issue 1916 WebKit: Universal XSS in HTMLFrameElementBase::isURLAllowed Source: XF Type: UNKNOWN webkit-htmlframeelementbase-xss(170273) Source: CCN Type: Packet Storm Security [10-28-2019] WebKit HTMLFrameElementBase::isURLAllowed Universal Cross Site Scripting Source: MISC Type: Vendor Advisory https://support.apple.com/en-us/HT210603 Source: MISC Type: Vendor Advisory https://support.apple.com/en-us/HT210604 Source: MISC Type: Vendor Advisory https://support.apple.com/en-us/HT210605 Source: MISC Type: Vendor Advisory https://support.apple.com/en-us/HT210635 Source: MISC Type: Vendor Advisory https://support.apple.com/en-us/HT210636 Source: MISC Type: Vendor Advisory https://support.apple.com/en-us/HT210637 Source: CCN Type: WebKit Web site WebKit Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [10-28-2019] | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |