vendor:
Gmail Mobile IOS Application
by:
Ali Raza Khawaja
6,8
CVSS
MEDIUM
Cross Site Scripting
79
CWE
Product Name: Gmail Mobile IOS Application
Affected Version From: Google Gmail Mobile IOS Application
Affected Version To: Google Gmail Mobile IOS Application
Patch Exists: NO
Related CWE: N/A
CPE: a:google:gmail_mobile_ios_application
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: iOS
2013
Gmail IOS Application Attachment Cross Site Scripting
A persistent / stored XSS vulnerability is detected in the official Google Gmail IOS Mobile Application. The vulnerability allows remote attackers to inject own malicious script code to a vulnerable module on application-side (persistent) via mail attachment feature. All iPad/iPhone users are affected directly with this vulnerability. During the testing it was discovered that .html files can be attached to outgoing emails. Viewing these attachments direct from the application will cause the malicious code to be executed.
Mitigation:
Ensure that all user-supplied input is properly sanitized and validated before being used in the application.