CVE-2023-38873

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-38873
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-38873.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-38873
Aliases
Published
2023-09-28T04:15:12Z
Modified
2024-05-14T12:58:32.841656Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer is vulnerable to Clickjacking. Clickjacking, also known as a "UI redress attack", is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they were intending to click on the top-level page. Thus, the attacker is "hijacking" clicks meant for their page and routing them to another page, most likely owned by another application, domain, or both.

References

Affected packages

Git / github.com/gugoan/economizzer

Affected ranges

Type
GIT
Repo
https://github.com/gugoan/economizzer
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

v0.*

v0.4-alpha
v0.8-alpha
v0.9-beta1