CVE-2020-9952Cross-site Scripting in Apple Icloud FOR Windows

Severity
7.1HIGHNVD
EPSS
0.5%
top 33.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16
Latest updateMay 24

Description

An input validation issue was addressed with improved input validation. This issue is fixed in iOS 14.0 and iPadOS 14.0, tvOS 14.0, watchOS 7.0, Safari 14.0, iCloud for Windows 11.4, iCloud for Windows 7.21. Processing maliciously crafted web content may lead to a cross site scripting attack.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:LExploitability: 2.8 | Impact: 3.7

Affected Packages12 packages

CVEListV5apple/icloud_for_windowsunspecifiediCloud for Windows 11.4+1
NVDapple/icloud11.011.4+1
CVEListV5apple/tvosunspecifiedtvOS 14.0
NVDapple/tvos< 14.0
CVEListV5apple/safariunspecifiedSafari 14.0

🔴Vulnerability Details

3
GHSA
GHSA-2hf4-pxq2-63h5: An input validation issue was addressed with improved input validation2022-05-24
OSV
CVE-2020-9952: An input validation issue was addressed with improved input validation2020-10-16
CVEList
CVE-2020-9952: An input validation issue was addressed with improved input validation2020-10-16

📋Vendor Advisories

7
Ubuntu
WebKitGTK vulnerabilities2020-11-26
Red Hat
webkitgtk: input validation issue may lead to a cross site scripting2020-11-23
Apple
CVE-2020-9952: iCloud for Windows 7.212020-09-24
Apple
CVE-2020-9952: iCloud for Windows 11.42020-09-24
Apple
CVE-2020-9952: watchOS 7.02020-09-16
CVE-2020-9952 — Cross-site Scripting in Apple | cvebase