CVE-2017-2510
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with pageshow events.
- Apple Safari
- ≤ 10.1
- Apple Iphone Os
- ≤ 10.3.1
- Fix
- Available
- CVSS 3.0
- 6.1 MEDIUM
- EPSS
- 3.9% (89th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2017-05-22
CVE-2017-2510 at NVD
4 known exploits for CVE-2017-2510
Proof-of-concept code and exploit modules indexed by Sploitus
WebKit enqueuePageshowEvent / enqueuePopstateEvent Universal XSS(CVE-2017-2510)
WebKit - enqueuePageshowEvent and enqueuePopstateEvent Universal Cross-Site Scripting Exploit
WebKit - 'enqueuePageshowEvent' / 'enqueuePopstateEvent' Universal Cross-Site Scripting
WebKit enqueuePageshowEvent / enqueuePopstateEvent Universal XSS