Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m8m6-9f93-23c4

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M unintentionally omit the X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site that contains a (1) FRAME, (2) IFRAME, or (3) OBJECT element.

Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M unintentionally omit the X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site that contains a (1) FRAME, (2) IFRAME, or (3) OBJECT element.

EPSS

Процентиль: 71%
0.00683
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
больше 10 лет назад

Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M unintentionally omit the X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site that contains a (1) FRAME, (2) IFRAME, or (3) OBJECT element.

EPSS

Процентиль: 71%
0.00683
Низкий

Дефекты

CWE-20