Clickjacking Vulnerability in OrientDB Server Community Edition
CVE-2015-2918

6.1MEDIUM

Key Information:

Vendor

Orientdb

Status
Vendor
CVE Published:
31 December 2015

What is CVE-2015-2918?

The Studio component in OrientDB Server Community Edition versions prior to 2.0.15 and 2.1.x before 2.1.1 lacks proper restrictions on the use of FRAME elements, which may allow remote attackers to exploit this weakness through crafted web pages. This can facilitate clickjacking attacks that potentially lead to unauthorized actions performed by users without their consent.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.