BCN Quark Quarking Password Manager 3.1.84 suffers from a clickjacking vulnerability caused by allowing * within web_accessible_resources. An attacker can take advantage of this vulnerability and cause significant harm.
References
Link | Resource |
---|---|
https://chrome.google.com/webstore/detail/quarking-password-manager/gfkmpfajamepgekgohcdnjogmeamcdmm?hl=en | Product Vendor Advisory |
http://seclists.org/fulldisclosure/2019/Jun/31 | Mailing List Third Party Advisory |
http://packetstormsecurity.com/files/153405/Quarking-Password-Manager-3.1.84-Clickjacking.html |
Configurations
Information
Published : 2019-06-24 12:15
Updated : 2020-08-24 10:37
NVD link : CVE-2019-12880
Mitre link : CVE-2019-12880
JSON object : View
CWE
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
Products Affected
bcnquark
- quarking_password_manager