Описание
The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer is vulnerable to Clickjacking. Clickjacking, also known as a "UI redress attack", is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they were intending to click on the top-level page. Thus, the attacker is "hijacking" clicks meant for their page and routing them to another page, most likely owned by another application, domain, or both.
Ссылки
- ExploitThird Party Advisory
- Product
- Product
- ExploitThird Party Advisory
- Product
- Product
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:economizzer:economizzer:0.9:beta1:*:*:*:wordpress:*:*
cpe:2.3:a:economizzer:economizzer:april_2023:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 43%
0.00206
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-1021
Связанные уязвимости
EPSS
Процентиль: 43%
0.00206
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-1021