CVE-2017-2493
WebKit HTMLObjectElement::updateWidget Universal XSS
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted elements on a web site.
Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 10.3 se han visto afectadas. Se han visto afectadas las versiones de Safari anteriores a la 10.1, las versiones de iCloud para Windows anteriores a la 6.2 y las versiones de tvOS anteriores a la 10.2. El problema afecta al componente "WebKit". Permite que atacantes remotos omitan la Política del Mismo Origen y obtengan información sensible mediante elementos manipulados en un sitio web.
WebKit suffers from a cross site scripting vulnerability in HTMLObjectElement::updateWidget.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-12-01 CVE Reserved
- 2017-05-25 CVE Published
- 2023-03-28 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.apple.com/HT207600 | 2019-03-08 | |
https://support.apple.com/HT207601 | 2019-03-08 | |
https://support.apple.com/HT207607 | 2019-03-08 | |
https://support.apple.com/HT207617 | 2019-03-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apple Search vendor "Apple" | Icloud Search vendor "Apple" for product "Icloud" | < 6.2 Search vendor "Apple" for product "Icloud" and version " < 6.2" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | < 10.1 Search vendor "Apple" for product "Safari" and version " < 10.1" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | < 10.3 Search vendor "Apple" for product "Iphone Os" and version " < 10.3" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Tvos Search vendor "Apple" for product "Tvos" | < 10.2 Search vendor "Apple" for product "Tvos" and version " < 10.2" | - |
Affected
|