vendor:
Safari
by:
Frans Rosén
7,5
CVSS
HIGH
Universal Cross Site Scripting
79
CWE
Product Name: Safari
Affected Version From: Safari 10
Affected Version To: Safari 10
Patch Exists: YES
Related CWE: None
CPE: a:apple:safari:10.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2017
CVE-2017-7089
A logic issue existed in the handling of the parent-tab which allowed maliciously crafted web content to lead to universal cross site scripting. An exploit by Frans Rosén was a data:text/html script which opened a parent-tab to apple.com and injected an image tag with an onerror attribute which triggered an alert with the document.domain and document.cookie.
Mitigation:
Improved state management