Clickjacking Vulnerability in Kerio Connect Product by GFI Software
CVE-2017-7440
6.5MEDIUM
What is CVE-2017-7440?
Kerio Connect versions 8.0.0 to 9.2.2 and the Kerio Connect Client for Windows and Mac (9.2.0 to 9.2.2) are susceptible to clickjacking. When the email preview feature is enabled, attackers can exploit this vulnerability by crafting malicious email messages that trick users into revealing sensitive information or executing unintended actions without their consent, potentially leading to unauthorized access.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved