Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9354-6mjp-r2vv

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Kerio Connect 8.0.0 through 9.2.2, and Kerio Connect Client desktop application for Windows and Mac 9.2.0 through 9.2.2, when e-mail preview is enabled, allows remote attackers to conduct clickjacking attacks via a crafted e-mail message.

Kerio Connect 8.0.0 through 9.2.2, and Kerio Connect Client desktop application for Windows and Mac 9.2.0 through 9.2.2, when e-mail preview is enabled, allows remote attackers to conduct clickjacking attacks via a crafted e-mail message.

EPSS

Процентиль: 46%
0.00234
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-1021
CWE-20

Связанные уязвимости

CVSS3: 6.5
nvd
почти 9 лет назад

Kerio Connect 8.0.0 through 9.2.2, and Kerio Connect Client desktop application for Windows and Mac 9.2.0 through 9.2.2, when e-mail preview is enabled, allows remote attackers to conduct clickjacking attacks via a crafted e-mail message.

EPSS

Процентиль: 46%
0.00234
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-1021
CWE-20