PT-2019-12997 · Bcn Quark · Bcn Quark Quarking Password Manager
Gionreale
·
Published
2019-06-24
·
Updated
2020-08-24
·
CVE-2019-12880
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
BCN Quark Quarking Password Manager version 3.1.84
Description
The issue is caused by allowing * within web accessible resources, which leads to a clickjacking vulnerability. An attacker can exploit this to cause significant harm.
Recommendations
For BCN Quark Quarking Password Manager version 3.1.84, consider restricting access to web accessible resources to prevent clickjacking attacks until a patch is available.
Fix
Clickjacking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bcn Quark Quarking Password Manager