Advisory ID : LINA/ADE-2023-0002

CVSS3.0 base score 4.1  AV:N/AC:L/UI:R/I:N/A:N

Date reported : 2022-10-27
Correction available  : 2022-12-23

Synopsis :

A vulnerability of type Clickjacking  has been detected

Product :

LINA / ADE admin console

Version :

From 5.0 to 6.0 of Lina

Problem type :

Clickjacking

Description :

An attacker may use this vulnerability to build a clickjacking scenario, either pretending to be a legitimate Lina WebUI but redirecting the actions or conversely pretending to offer some other service while directing the requests towards Lina WebUI. 

Anti-clickjacking headers protect sites from such attacks. 

Mitigations or workaround :

We strongly recommend upgrading Lina to 6.0 or higher to avoid these issues.

 

Contact




    Skip to content