CVE-2021-1825
published 2021-09-08CVE-2021-1825: An input validation issue was addressed with improved input validation. This issue is fixed in iTunes 12.11.3 for Windows, iCloud for Windows 12.3, macOS Big…
PriorityP429medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.36%
68.6th percentile
An input validation issue was addressed with improved input validation. This issue is fixed in iTunes 12.11.3 for Windows, iCloud for Windows 12.3, macOS Big Sur 11.3, Safari 14.1, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may lead to a cross site scripting attack.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud | < 12.3 | 12.3 |
| apple | icloud_for_windows | >= unspecified < 12.3 | 12.3 |
| apple | ios_14.5_and_ipados | — | — |
| apple | ios_and_ipados | >= unspecified < 14.5 | 14.5 |
| apple | ipados | < 14.5 | 14.5 |
| apple | iphone_os | < 14.5 | 14.5 |
| apple | itunes | < 12.11.3 | 12.11.3 |
| apple | itunes_for_windows | >= unspecified < 12.11 | 12.11 |
| apple | macos | >= 11.0 < 11.3 | 11.3 |
| apple | macos | >= unspecified < 11.3 | 11.3 |
| apple | macos_big_sur | — | — |
| apple | safari | < 14.1 | 14.1 |
| apple | safari | >= unspecified < 14.1 | 14.1 |
| apple | tvos | < 14.5 | 14.5 |
| apple | tvos | >= unspecified < 14.5 | 14.5 |
| apple | watchos | < 7.4 | 7.4 |
| apple | watchos | >= unspecified < 7.4 | 7.4 |
| debian | webkit2gtk | < webkit2gtk 2.30.1-1 (bookworm) | webkit2gtk 2.30.1-1 (bookworm) |
| debian | wpewebkit | < webkit2gtk 2.30.1-1 (bookworm) | webkit2gtk 2.30.1-1 (bookworm) |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
webkitgtk: Input validation issue leading to cross site scripting attack
vendor_redhat·2021-07-28·CVSS 6.1
CVE-2021-1825 [MEDIUM] CWE-20 webkitgtk: Input validation issue leading to cross site scripting attack
webkitgtk: Input validation issue leading to cross site scripting attack
An input validation issue was addressed with improved input validation. This issue is fixed in iTunes 12.11.3 for Windows, iCloud for Windows 12.3, macOS Big Sur 11.3, Safari 14.1, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may lead to a cross site scripting attack.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Out of support scope
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Out of support scope
Package: webkit2gtk3 (Red Hat Enterprise Linux 9) - Not affected
Apple
CVE-2021-1825: iOS 14.5 and iPadOS 14.5
vendor_apple·2021-04-26·CVSS 6.1
CVE-2021-1825 [MEDIUM] CVE-2021-1825: iOS 14.5 and iPadOS 14.5
Apple Security Update: About the security content of iOS 14.5 and iPadOS 14.5
Product: iOS 14.5 and iPadOS
Version: 14.5
CVE: CVE-2021-1825
Component: WebKit
Impact: Processing maliciously crafted web content may lead to a cross site scripting attack
Description: An input validation issue was addressed with improved input validation.
Apple
CVE-2021-1825: macOS Big Sur 11.3
vendor_apple·2021-04-26·CVSS 6.1
CVE-2021-1825 [MEDIUM] CVE-2021-1825: macOS Big Sur 11.3
Apple Security Update: About the security content of macOS Big Sur 11.3
Product: macOS Big Sur
Version: 11.3
CVE: CVE-2021-1825
Component: WebKit
Impact: Processing maliciously crafted web content may lead to a cross site scripting attack
Description: An input validation issue was addressed with improved input validation.
Debian
CVE-2021-1825: webkit2gtk - An input validation issue was addressed with improved input validation. This iss...
vendor_debian·2021·CVSS 6.1
CVE-2021-1825 [MEDIUM] CVE-2021-1825: webkit2gtk - An input validation issue was addressed with improved input validation. This iss...
An input validation issue was addressed with improved input validation. This issue is fixed in iTunes 12.11.3 for Windows, iCloud for Windows 12.3, macOS Big Sur 11.3, Safari 14.1, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may lead to a cross site scripting attack.
Scope: local
bookworm: resolved (fixed in 2.30.1-1)
bullseye: resolved (fixed in 2.30.1-1)
forky: resolved (fixed in 2.30.1-1)
sid: resolved (fixed in 2.30.1-1)
trixie: resolved (fixed in 2.30.1-1)
GHSA
GHSA-7gx9-m7c6-98gf: An input validation issue was addressed with improved input validation
ghsa_unreviewed·2022-05-24
CVE-2021-1825 [MEDIUM] CWE-79 GHSA-7gx9-m7c6-98gf: An input validation issue was addressed with improved input validation
An input validation issue was addressed with improved input validation. This issue is fixed in iTunes 12.11.3 for Windows, iCloud for Windows 12.3, macOS Big Sur 11.3, Safari 14.1, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may lead to a cross site scripting attack.
OSV
CVE-2021-1825: An input validation issue was addressed with improved input validation
osv·2021-09-08·CVSS 6.1
CVE-2021-1825 [MEDIUM] CVE-2021-1825: An input validation issue was addressed with improved input validation
An input validation issue was addressed with improved input validation. This issue is fixed in iTunes 12.11.3 for Windows, iCloud for Windows 12.3, macOS Big Sur 11.3, Safari 14.1, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may lead to a cross site scripting attack.
No detection rules found.
Exploit-DB
MyBB 1.8.25 - Poll Vote Count SQL Injection
exploitdb·2021-03-23·CVSS 6.1
CVE-2021-27946 [MEDIUM] MyBB 1.8.25 - Poll Vote Count SQL Injection
MyBB 1.8.25 - Poll Vote Count SQL Injection
---
# Exploit Title: MyBB 1.8.25 - Poll Vote Count SQL Injection
# Exploit Author: SivertPL ([email protected])
# Date: 20.03.2021
# Description: Lack of sanitization in the "votes[]" parameter in "Edit Poll" causes a second-order semi-blind SQL Injection that is triggered when performing a "Move/Copy" operation on the thread.
# Sofware Link: https://resources.mybb.com/downloads/mybb_1825.zip
# CVE: CVE-2021-27946
References:
1) https://portswigger.net/daily-swig/chained-vulnerabilities-used-to-take-control-of-mybb-forums
2) https://vuldb.com/?id.171307
3) https://github.com/mybb/mybb/commit/aa415f08bce01f95a8319b707bb18eb67833f4c1.patch
In order to trigger the vulnerability, you must have permission to edit polls.
Moderators and admin
Exploit-DB
MyBB 1.8.25 - Chained Remote Command Execution
exploitdb·2021-03-22·CVSS 6.1
CVE-2021-27890 [MEDIUM] MyBB 1.8.25 - Chained Remote Command Execution
MyBB 1.8.25 - Chained Remote Command Execution
---
# Exploit Title: MyBB 1.8.25 - Chained Remote Command Execution
# Exploit Author: SivertPL ([email protected])
# Date: 19.03.2021
# Description: Nested autourl Stored XSS -> templateset second order SQL Injection leading to RCE through improper string interpolation in eval().
# Software Link: https://resources.mybb.com/downloads/mybb_1825.zip
# CVE: CVE-2021-27889, CVE-2021-27890
# Reference: https://portswigger.net/daily-swig/chained-vulnerabilities-used-to-take-control-of-mybb-forums
# The exploit requires the target administrator to have a valid ACP session.
# Proof of Concept Video: https://www.youtube.com/watch?v=xU1Y9_bgoFQ
# Guide:
1) In order to escape various checks, the XSS has to download this .js file from an external
No writeups or analysis indexed.
https://support.apple.com/en-us/HT212317https://support.apple.com/en-us/HT212318https://support.apple.com/en-us/HT212319https://support.apple.com/en-us/HT212321https://support.apple.com/en-us/HT212323https://support.apple.com/en-us/HT212324https://support.apple.com/en-us/HT212325https://support.apple.com/en-us/HT212317https://support.apple.com/en-us/HT212318https://support.apple.com/en-us/HT212319https://support.apple.com/en-us/HT212321https://support.apple.com/en-us/HT212323https://support.apple.com/en-us/HT212324https://support.apple.com/en-us/HT212325
2021-09-08
Published