Clickjacking Vulnerability in Dell EMC AppSync
CVE-2022-22552

6.9MEDIUM

Key Information:

Vendor
Dell
Status
Vendor
CVE Published:
21 January 2022

Summary

Dell EMC AppSync versions 3.9 through 4.3 are susceptible to a clickjacking vulnerability. This issue permits remote unauthenticated attackers to potentially manipulate the user interface, tricking victims into performing unintended actions without their knowledge. Such operations could lead to changes in user state and unauthorized access to sensitive functionalities.

Affected Version(s)

AppSync < 4.4

References

CVSS V3.1

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.