Clickjacking Vulnerability in Cybozu Remote Service Client Certificate Management
CVE-2018-16172
6.5MEDIUM
What is CVE-2018-16172?
A security flaw exists in the client certificate management screen of Cybozu Remote Service, specifically in versions 3.0.0 to 3.1.8. This flaw makes the application vulnerable to clickjacking attacks, allowing remote attackers to deceive users into unintentionally deleting registered client certificates. By exploiting this weakness, attackers can manipulate the user interface, potentially leading to unauthorized actions without the user's informed consent. For further details and mitigation strategies, refer to the advisory provided by Cybozu.
Affected Version(s)
Cybozu Remote Service 3.0.0 to 3.1.8