VYPR

CWE-1021

Improper Restriction of Rendered UI Layers or Frames

BaseIncomplete

Description

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-103 · CAPEC-181 · CAPEC-222 · CAPEC-504 · CAPEC-506 · CAPEC-587 · CAPEC-654

CVEs mapped to this weakness (406)

page 9 of 21
  • CVE-2022-34162MedAug 1, 2022
    risk 0.40cvss 6.1epss 0.01

    IBM CICS TX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against…

  • CVE-2022-24733MedMar 14, 2022
    risk 0.40cvss 6.1epss 0.01

    Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, it is possible for a page controlled by an attacker to load the website within an iframe. This will enable a clickjacking attack, in which the attacker's page overlays the target…

  • CVE-2021-46708MedMar 11, 2022
    risk 0.40cvss 6.1epss 0.01

    The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and…

  • CVE-2021-41657MedMar 10, 2022
    risk 0.40cvss 6.1epss 0.01

    SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a clickjacking attack.

  • CVE-2018-19957MedSep 10, 2021
    risk 0.40cvss 6.1epss 0.01

    A vulnerability involving insufficient HTTP security headers has been reported to affect QNAP NAS running QTS, QuTS hero, and QuTScloud. This vulnerability allows remote attackers to launch privacy and security attacks. We have already fixed this vulnerability in the following…

  • CVE-2021-27467MedMay 20, 2021
    risk 0.40cvss 6.1epss 0.01

    A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected product’s web interface allows an attacker to route click or keystroke to another page provided by the attacker to gain unauthorized access to sensitive information.

  • CVE-2021-23955MedFeb 26, 2021
    risk 0.40cvss 6.1epss 0.01

    The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to clickjacking attacks. This vulnerability affects Firefox < 85.

  • CVE-2021-21444MedFeb 9, 2021
    risk 0.40cvss 6.1epss 0.01

    SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be predictably treated by all user agents. This could, as a result, nullify the added X-Frame-Options header leading to Clickjacking…

  • CVE-2020-5020MedJan 8, 2021
    risk 0.40cvss 6.1epss 0.01

    IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly…

  • CVE-2020-26962MedDec 9, 2020
    risk 0.40cvss 6.1epss 0.01

    Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as well as be read across partitions in dynamic first party isolation. This vulnerability affects Firefox…

  • CVE-2020-5679MedDec 3, 2020
    risk 0.40cvss 6.1epss 0.01

    Improper restriction of rendered UI layers or frames in EC-CUBE versions from 3.0.0 to 3.0.18 leads to clickjacking attacks. If a user accesses a specially crafted page while logged into the administrative page, unintended operations may be conducted.

  • CVE-2019-8771MedOct 27, 2020
    risk 0.40cvss 6.1epss 0.01

    This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 13.0.1, iOS 13. Maliciously crafted web content may violate iframe sandboxing policy.

  • CVE-2020-4727MedSep 25, 2020
    risk 0.40cvss 6.1epss 0.01

    IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch…

  • CVE-2020-13174MedAug 11, 2020
    risk 0.40cvss 6.1epss 0.01

    The web server in the Teradici Managament console versions 20.04 and 20.01.1 did not properly set the X-Frame-Options HTTP header, which could allow an attacker to trick a user into clicking a malicious link via clickjacking.

  • CVE-2020-9444MedApr 20, 2020
    risk 0.40cvss 6.1epss 0.01

    Zulip Server before 2.1.3 allows reverse tabnabbing via the Markdown functionality.

  • CVE-2019-4548MedFeb 4, 2020
    risk 0.40cvss 6.1epss 0.01

    IBM Security Directory Server 6.4.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch…

  • CVE-2019-4742MedDec 20, 2019
    risk 0.40cvss 6.1epss 0.01

    IBM Financial Transaction Manager 3.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch…

  • CVE-2019-4215MedNov 22, 2019
    risk 0.40cvss 6.1epss 0.01

    IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly…

  • CVE-2019-4109MedSep 30, 2019
    risk 0.40cvss 6.1epss 0.01

    IBM WebSphere eXtreme Scale 8.6 Admin Console could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly…

  • CVE-2019-1975MedSep 18, 2019
    risk 0.40cvss 6.1epss 0.01

    A vulnerability in the web-based interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to execute a cross-frame scripting (XFS) attack on an affected device. This vulnerability is due to insufficient HTML iframe protection. An attacker could…