CVE-2020-9843Cross-site Scripting in Apple Icloud FOR Windows

Severity
7.1HIGHNVD
EPSS
0.7%
top 27.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 9
Latest updateMay 24

Description

An input validation issue was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to a cross site scripting attack.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:LExploitability: 2.8 | Impact: 3.7

Affected Packages13 packages

CVEListV5apple/icloud_for_windowsunspecifiediCloud for Windows 11.2+1
CVEListV5apple/itunes_for_windowsunspecifiediTunes 12.10.7 for Windows
NVDapple/icloud11.011.2+1
CVEListV5apple/tvosunspecifiedtvOS 13.4.5
NVDapple/tvos< 13.4.5

🔴Vulnerability Details

3
GHSA
GHSA-9c59-pwqp-c9gc: An input validation issue was addressed with improved input validation2022-05-24
CVEList
CVE-2020-9843: An input validation issue was addressed with improved input validation2020-06-09
OSV
CVE-2020-9843: An input validation issue was addressed with improved input validation2020-06-09

📋Vendor Advisories

4
Oracle
Oracle Oracle Database Server Risk Matrix: Core RDBMS (zlib) — CVE-2016-98432020-07-15
Ubuntu
WebKitGTK+ vulnerabilities2020-07-14
Red Hat
webkitgtk: Input validation issue may lead to cross site scripting2020-07-10
Debian
CVE-2020-9843: webkit2gtk - An input validation issue was addressed with improved input validation. This iss...2020

💬Community

1
Bugzilla
CVE-2020-9843 webkitgtk: Input validation issue may lead to cross site scripting2020-09-16
CVE-2020-9843 — Cross-site Scripting in Apple | cvebase