Clickjacking Vulnerability in Typecho by Typecho
CVE-2024-57369

6.4MEDIUM

Key Information:

Vendor

Typecho

Status
Vendor
CVE Published:
17 January 2025

What is CVE-2024-57369?

A clickjacking vulnerability was identified in Typecho v1.2.1, allowing attackers to manipulate the web application's interface. This security flaw can enable malicious actors to trick users into clicking on elements that are disguised under legitimate content. By exploiting this vulnerability, attackers could potentially gain unauthorized access to sensitive actions, impacting the confidentiality and integrity of user data. It is crucial for Typecho users to implement protective measures to mitigate this risk and ensure the security of their web environments.

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.