First published: Fri Mar 30 2018(Updated: )
On Samsung mobile devices with M(6.0) software, the Email application allows XSS via an event attribute and arbitrary file loading via a src attribute, aka SVE-2017-10747.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Mobile | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9140 has a medium severity rating due to its potential for cross-site scripting and file loading vulnerabilities.
To fix CVE-2018-9140, ensure that your Samsung mobile device is updated to the latest software version provided by Samsung.
CVE-2018-9140 affects Samsung mobile devices running Android M (6.0) software.
CVE-2018-9140 exploits vulnerabilities related to cross-site scripting (XSS) and arbitrary file loading.
Yes, CVE-2018-9140 is specific to the Email application on Samsung devices running Android M (6.0).