Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wm6w-5h88-p758

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Form Autofill feature in Apple Safari before 6.0.1 does not restrict the filled fields to the set of fields contained in an Autofill popover, which allows remote attackers to obtain the Me card from an Address Book via a crafted web site.

The Form Autofill feature in Apple Safari before 6.0.1 does not restrict the filled fields to the set of fields contained in an Autofill popover, which allows remote attackers to obtain the Me card from an Address Book via a crafted web site.

EPSS

Процентиль: 55%
0.00319
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
больше 13 лет назад

The Form Autofill feature in Apple Safari before 6.0.1 does not restrict the filled fields to the set of fields contained in an Autofill popover, which allows remote attackers to obtain the Me card from an Address Book via a crafted web site.

EPSS

Процентиль: 55%
0.00319
Низкий

Дефекты

CWE-200