CVE-2018-4374Cross-site Scripting in Apple Icloud

Severity
6.1MEDIUMNVD
EPSS
0.5%
top 33.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 3
Latest updateMay 14

Description

A logic issue was addressed with improved validation. This issue affected versions prior to iOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages5 packages

NVDapple/icloud< 7.8
NVDapple/itunes< 12.9.1
NVDapple/safari< 12.0.1
NVDapple/watchos< 5.1
NVDapple/iphone_os< 12.1

🔴Vulnerability Details

2
GHSA
GHSA-fr65-9gh3-8r3f: A logic issue was addressed with improved validation2022-05-14
CVEList
CVE-2018-4374: A logic issue was addressed with improved validation2019-04-03

📋Vendor Advisories

5
Apple
CVE-2018-4374: Safari 12.0.12018-10-30
Apple
CVE-2018-4374: watchOS 5.12018-10-30
Apple
CVE-2018-4374: iCloud for Windows 7.82018-10-30
Apple
CVE-2018-4374: iTunes 12.9.1 for Windows2018-10-30
Apple
CVE-2018-4374: iOS 12.12018-10-30
CVE-2018-4374 — Cross-site Scripting in Apple Icloud | cvebase