CVE-2021-36214: XSS
Published Jul 13, 2021
·Updated
LINE client for iOS before 10.16.3 allows cross site script with specific header in WebView.
Affected Software
1 affected component
linecorp Line Iphone Os<10.16.3
Event History
Jul 13, 2021
CVE Published
via MITRE·05:47 PM
Data Sourced
via MITRE·05:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-36214?
CVE-2021-36214 is a vulnerability that allows for cross-site scripting in the LINE client for iOS before version 10.16.3.
2
How does CVE-2021-36214 affect the LINE client for iOS?
CVE-2021-36214 affects the LINE client for iOS before version 10.16.3, allowing for cross-site scripting with a specific header in the WebView component.
3
What is the severity of CVE-2021-36214?
The severity of CVE-2021-36214 is medium with a CVSS score of 6.1.
4
How can I fix CVE-2021-36214 in the LINE client for iOS?
To fix CVE-2021-36214 in the LINE client for iOS, make sure to update to version 10.16.3 or later.
5
What is cross-site scripting (XSS)?
Cross-site scripting (XSS) is a web security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.