CVE-2019-8505Cross-site Scripting in Apple Safari

Severity
6.1MEDIUMNVD
EPSS
0.2%
top 54.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 18
Latest updateMay 24

Description

A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, Safari 12.1. Enabling the Safari Reader feature on a maliciously crafted webpage may lead to universal cross site scripting.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

CVEListV5apple/safariunspecifiedSafari 12.1
NVDapple/safari< 12.1
CVEListV5apple/iosunspecifiediOS 12.2
NVDapple/iphone_os< 12.2

🔴Vulnerability Details

2
GHSA
GHSA-m5fg-phfr-7975: A logic issue was addressed with improved validation2022-05-24
CVEList
CVE-2019-8505: A logic issue was addressed with improved validation2019-12-18

📋Vendor Advisories

2
Apple
CVE-2019-8505: Safari 12.12019-03-25
Apple
CVE-2019-8505: iOS 12.22019-03-25
CVE-2019-8505 — Cross-site Scripting in Apple Safari | cvebase