AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-16873

MEDIUM · CVSS 4.7 EPSS 3.97%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-09-11 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.7. It affects Microsoft, Android, Java.

CVE
CVE-2020-16873
Severity
MEDIUM
CVSS
4.7
EPSS
3.97%
Microsoft Android Java

Original NVD Description

<p>A spoofing vulnerability manifests in Microsoft Xamarin.Forms due to the default settings on Android WebView version prior to 83.0.4103.106. This vulnerability could allow an attacker to execute arbitrary Javascript code on a target system.</p> <p>For the attack to be successful, the targeted user would need to browse to a malicious website or a website serving the malicious code through Xamarin.Forms.</p> <p>The security update addresses this vulnerability by preventing the malicious Javascript from running in the WebView.</p>

Related CVEs

Other vulnerabilities affecting the same vendor(s)