Cross-Site Scripting and file upload vulnerabilities in Samsung Email application
CVE-2018-9140
6.1MEDIUM
What is CVE-2018-9140?
The Samsung Email application on mobile devices utilizing M(6.0) software is susceptible to a class of vulnerabilities that allows attackers to exploit cross-site scripting (XSS) via event attributes. Additionally, the application permits arbitrary file loading through its src attribute, potentially exposing user data and creating severe security risks. Users are advised to update their software to mitigate these issues.