Clickjacking Vulnerability in Cybozu Remote Service Client Certificate Management
CVE-2018-16172

6.5MEDIUM

Key Information:

Vendor

Cybozu

Vendor
CVE Published:
9 January 2019

What is CVE-2018-16172?

A security flaw exists in the client certificate management screen of Cybozu Remote Service, specifically in versions 3.0.0 to 3.1.8. This flaw makes the application vulnerable to clickjacking attacks, allowing remote attackers to deceive users into unintentionally deleting registered client certificates. By exploiting this weakness, attackers can manipulate the user interface, potentially leading to unauthorized actions without the user's informed consent. For further details and mitigation strategies, refer to the advisory provided by Cybozu.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Cybozu Remote Service 3.0.0 to 3.1.8

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.