CVE-2017-7440

K

erio Connect 8.0.0 through 9.2.2, and Kerio Connect Client desktop application for Windows and Mac 9.2.0 through 9.2.2, when e-mail preview is enabled, allows remote attackers to conduct clickjacking attacks via a crafted e-mail message.

Configurations

Configuration 1 (hide)

cpe:2.3:a:gfi:kerio_connect:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:gfi:kerio_connect_client:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:31

Type Values Removed Values Added
References () https://www.gfi.com/support/products/Clickjacking-vulnerability-in-Kerio-Connect-8-and-9-CVE-2017-7440 - Patch, Vendor Advisory () https://www.gfi.com/support/products/Clickjacking-vulnerability-in-Kerio-Connect-8-and-9-CVE-2017-7440 - Patch, Vendor Advisory

Information

Published : 2017-05-02 14:59

Updated : 2025-04-20 01:37


NVD link : CVE-2017-7440

Mitre link : CVE-2017-7440

CVE.ORG link : CVE-2017-7440


JSON object : View

CWE
CWE-1021

Improper Restriction of Rendered UI Layers or Frames