CVE-2017-7038
MEDIUMApple - XSS
Title source: llmDescription
A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component.
Exploits (1)
nomisec
WORKING POC
3 stars
by ansjdnakjdnajkd · poc
https://github.com/ansjdnakjdnajkd/CVE-2017-7038
References (6)
Scores
CVSS v3
6.1
EPSS
0.0561
EPSS Percentile
90.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (5)
n/a/n/a
apple/safari
< 10.1.2
apple/iphone_os
< 10.3.3
apple/tvos
< 10.2.2
apple/webkit
Published
Jul 20, 2017
Tracked Since
Feb 18, 2026