Описание
LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable to 'clickjacking'. This allows an attacker to trick a targetted user to execute unintended actions.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support, was needs-triage |
| devel | not-affected | 1.6.33+ds-2.2 |
| esm-apps/bionic | released | 1.4.42+ds-1ubuntu0.1~esm1 |
| esm-apps/focal | released | 1.6.9+ds-1ubuntu0.1 |
| esm-apps/jammy | not-affected | 1.6.33+ds-1 |
| esm-apps/noble | not-affected | 1.6.33+ds-2.1 |
| esm-apps/xenial | released | 1.3.46-1ubuntu0.1~esm1 |
| esm-infra-legacy/trusty | DNE | |
| focal | released | 1.6.9+ds-1ubuntu0.1 |
| hirsute | released | 1.6.9+ds-2ubuntu0.1 |
Показывать по
EPSS
4.3 Medium
CVSS2
5.9 Medium
CVSS3
Связанные уязвимости
LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable to 'clickjacking'. This allows an attacker to trick a targetted user to execute unintended actions.
LedgerSMB does not sufficiently guard against being wrapped by other s ...
LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable to 'clickjacking'. This allows an attacker to trick a targetted user to execute unintended actions.
EPSS
4.3 Medium
CVSS2
5.9 Medium
CVSS3