CVE-2019-9147

MEDIUM

Mailvelope < 3.1.0 - Clickjacking via Settings Page Bypass

Title source: llm
STIX 2.1

Description

Mailvelope prior to 3.1.0 is vulnerable to a clickjacking attack against the settings page. As the settings page is intended to be accessible from web applications, the browser's extension isolation mechanisms are disabled (web_accessible_resources). Mailvelope implements additional measures to prevent web applications from directly embedding the settings page, but this mechanism can be bypassed.

Scores

CVSS v3 4.3
EPSS 0.0144
EPSS Percentile 69.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-1021
Status published
Products (1)
mailvelope/mailvelope < 3.1.0
Published Jul 09, 2019
Tracked Since Feb 18, 2026