Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-20801

Опубликовано: 18 мая 2020
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server allows for cross-origin requests from any domain, and the WebSocket server lacks authorization control. Any web site can execute JavaScript code (that accesses a user's data) via cross-origin requests.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:readdle:documents:*:*:*:*:*:iphone_os:*:*
Версия до 6.9.7 (исключая)

EPSS

Процентиль: 44%
0.00213
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-862

Связанные уязвимости

github
больше 3 лет назад

An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server allows for cross-origin requests from any domain, and the WebSocket server lacks authorization control. Any web site can execute JavaScript code (that accesses a user's data) via cross-origin requests.

EPSS

Процентиль: 44%
0.00213
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-862