CVE-2018-4133: XSS
An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involves the "WebKit" component. A Safari cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Other sources
WebKit. A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-4102
- CVE-2018-4116
- CVE-2018-4186
- CVE-2018-4137
- CVE-2018-4101
- CVE-2018-4114
- CVE-2018-4118
- CVE-2018-4119
- CVE-2018-4120
- CVE-2018-4121
- CVE-2018-4122
- CVE-2018-4125
- CVE-2018-4127
- CVE-2018-4128
- CVE-2018-4129
- CVE-2018-4130
- CVE-2018-4161
- CVE-2018-4162
- CVE-2018-4163
- CVE-2018-4165
- CVE-2018-4133
- CVE-2018-4113
- CVE-2018-4146
- CVE-2018-4117
- CVE-2018-4207
- CVE-2018-4208
- CVE-2018-4209
- CVE-2018-4210
- CVE-2018-4212
- CVE-2018-4213
- CVE-2018-4145
Frequently Asked Questions
What is CVE-2018-4133?
CVE-2018-4133 is a cross-site scripting (XSS) vulnerability in Safari before version 11.1.
Which software versions are affected by CVE-2018-4133?
Safari versions up to and excluding 11.1 are affected.
How can CVE-2018-4133 be exploited?
Remote attackers can exploit this vulnerability by injecting arbitrary web script or HTML via a crafted URL.
What is the severity of CVE-2018-4133?
CVE-2018-4133 has a severity rating of 6.1 (Medium).
Are there any references for CVE-2018-4133?
Yes, you can find references for CVE-2018-4133 at the following links: http://www.securityfocus.com/bid/103580, http://www.securitytracker.com/id/1040606, https://security.gentoo.org/glsa/201808-04