PT-2022-20882 · Rdiffweb · Rdiffweb

Published

2022-09-08

·

Updated

2022-09-14

·

CVE-2022-3167

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions rdiffweb versions prior to 2.4.1
Description The issue is related to improper restriction of rendered UI layers or frames, allowing attackers to perform clickjacking attacks. This can trick victims into performing actions such as entering passwords, liking or deleting posts, and/or initiating an account deletion.
Recommendations For versions prior to 2.4.1, update to version 2.4.1 to resolve the issue. As a temporary workaround, consider restricting access to sensitive features that can be exploited through clickjacking attacks until the update is applied.

Exploit

Fix

Clickjacking

Weakness Enumeration

Related Identifiers

CVE-2022-3167
GHSA-M379-X4XC-38X9
PYSEC-2022-268

Affected Products

Rdiffweb