Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w9gh-cppp-xrgm

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A missing X-Frame-Options header in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application could be used by a remote attacker for clickjacking, as demonstrated by triggering an API page request.

A missing X-Frame-Options header in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application could be used by a remote attacker for clickjacking, as demonstrated by triggering an API page request.

EPSS

Процентиль: 45%
0.00226
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-1021

Связанные уязвимости

CVSS3: 6.5
nvd
больше 7 лет назад

A missing X-Frame-Options header in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application could be used by a remote attacker for clickjacking, as demonstrated by triggering an API page request.

EPSS

Процентиль: 45%
0.00226
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-1021