Clickjacking Vulnerability in Clibo Manager's Login Page
CVE-2024-10454
6.1MEDIUM
Key Information:
- Vendor
- Clibo Manager
- Status
- Clibo Manager
- Vendor
- CVE Published:
- 31 October 2024
Summary
Clickjacking vulnerability in Clibo Manager v1.1.9.12 in the '/public/login' directory, a login panel. This vulnerability occurs due to the absence of an X-Frame-Options server-side header. An attacker could overlay a transparent iframe to perform click hijacking on victims.
Affected Version(s)
Clibo Manager 1.1.9.12
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database
Credit
David Padilla Alvarado