Описание
A validation issue was addressed with improved input sanitization. This issue is fixed in iTunes U 3.8.3. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.
Уязвимые конфигурации
Конфигурация 1Версия до 3.8.3 (исключая)
cpe:2.3:a:apple:itunes_u:*:*:*:*:*:*:*:*
EPSS
Процентиль: 82%
0.01637
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-20
EPSS
Процентиль: 82%
0.01637
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-20