CWE-1021

Improper Restriction of Rendered UI Layers or Frames

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.

401 vulnerabilities with CWE-1021
CVE-2024-26167 MEDIUM
Microsoft Edge < 122.0.2365.92 - Spoofing via UI Layer Restriction Bypass
CVSS 4.3
CVE-2024-1890 MEDIUM
Sunny WebBox Firmware < 1.61 - Clickjacking via Malicious Link
CVSS 6.4
CVE-2024-1550 MEDIUM
Firefox < 123 and ESR < 115.8 - UI Spoofing via Fullscreen and Pointer Lock
CVSS 6.1
CVE-2024-20810 LOW
Smart Suggestions <SMR Feb-2024 Release 1 - Info Disclosure
CVSS 3.3
CVE-2024-0669 MEDIUM
Plone < 6.0.5 - Cross-Frame Scripting via Malicious URL
CVSS 6.3
CVE-2023-7013 MEDIUM
Google Chrome <119.0.6045.105 - XSS
CVSS 4.7
CVE-2023-42011 MEDIUM
IBM Sterling B2B Integrator Standard Edition 6.1-6.2 - Info Disclosure
CVSS 4.3
CVE-2023-47774 MEDIUM
Jetpack < 12.7 - Clickjacking via Improper UI Layer Restriction
CVSS 5.4
CVE-2023-45698 MEDIUM
HCL Sametime Chat and Meetings - Clickjacking via Outlook Add-in
CVSS 4.8
CVE-2023-6093 MEDIUM
OnCell G3150A-LTE Series <1.3 - XSS
CVSS 5.3
CVE-2023-6867 MEDIUM
Firefox < 121.0 and Firefox ESR < 115.6 - Clickjacking via Permission Prompt Timing
CVSS 6.1
CVE-2023-4958 MEDIUM
Red Hat Advanced Cluster Security - CSRF
CVSS 6.1
CVE-2023-2265 MEDIUM
SEL-411L Firmware r118-v0 to r118-v4 - Unauthenticated Clickjacking via UI Layer Manipulation
CVSS 4.3
CVE-2023-6211 MEDIUM
Firefox < 120.0 - UI Spoofing via HTTPS-Only Mode Exception Clickjacking
CVSS 6.5
CVE-2023-6206 MEDIUM
Firefox < 120, Firefox ESR < 115.5.0, Thunderbird < 115.5 - Info Di...
CVSS 5.4
CVE-2023-47311 MEDIUM
Yamcs 5.8.6 - Command Injection
CVSS 6.1
CVE-2023-4956 MEDIUM
Quay - Clickjacking in Config-Editor Page
CVSS 6.5
CVE-2023-36920 MEDIUM
SAP Enable Now - WPB_MANAGER <1.0-ENABLE_NOW_CONSUMP_DEL 1704 - XSS
CVSS 6.1
CVE-2023-5721 MEDIUM
Firefox < 119.0 and Firefox ESR < 115.4 - Unintended UI Layer Activation via Insufficient Activation-Delay
CVSS 4.3
CVE-2023-41897 HIGH
Home Assistant < 2023.9.0 - Clickjacking via Missing X-Frame-Options Header
CVSS 8.8
CVE-2023-5103 MEDIUM
SICK APU0200 Firmware < 4.0.0.6 - Unauthenticated Sensitive Information Exposure via Clickjacking
CVSS 4.3
CVE-2023-38873 MEDIUM
gugoan Economizzer <0.9-beta1 - CSRF
CVSS 6.5
CVE-2023-30961 MEDIUM
Palantir Gotham - Info Disclosure
CVSS 6.5
CVE-2023-0654 LOW
Cloudflare WARP < 6.29 - Tapjacking via Misconfigured UI Layer
CVSS 3.9
CVE-2023-4229 MEDIUM
Moxa ioLogik E4200 Firmware < 1.6 - Clickjacking
CVSS 4.3
Details
Vulnerabilities 401