Vulnerabilities > Cloudmagic

DATE CVE VULNERABILITY TITLE RISK
2020-03-18 CVE-2019-12365 Cross-site Scripting vulnerability in Cloudmagic Newton 10.0.23
The Newton application through 10.0.23 for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.
network
low complexity
cloudmagic CWE-79
6.1