Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gc95-5mmp-mp6j

Опубликовано: 28 сент. 2023
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Economizzer vulnerable to Clickjacking

The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer is vulnerable to Clickjacking. Clickjacking, also known as a "UI redress attack", is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they were intending to click on the top-level page. Thus, the attacker is "hijacking" clicks meant for their page and routing them to another page, most likely owned by another application, domain, or both.

Пакеты

Наименование

gugoan/economizzer

composer
Затронутые версииВерсия исправления

<= 0.9-beta1

Отсутствует

EPSS

Процентиль: 43%
0.00206
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-1021

Связанные уязвимости

CVSS3: 6.5
nvd
больше 2 лет назад

The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer is vulnerable to Clickjacking. Clickjacking, also known as a "UI redress attack", is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they were intending to click on the top-level page. Thus, the attacker is "hijacking" clicks meant for their page and routing them to another page, most likely owned by another application, domain, or both.

EPSS

Процентиль: 43%
0.00206
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-1021