Description
Western Digital My Cloud Home and ibi devices before 2.2.0 allow clickjacking on sign-in pages.
References (3)
Core 3
Core References
Release Notes x_refsource_misc
https://support.wdc.com/downloads.aspx?g=907&lang=en
Broken Link, Vendor Advisory x_refsource_confirm
https://www.westerndigital.com/support/productsecurity/wdc-19012-my-cloud-home-and-ibi-portal-websites-clickjacking-vulnerability
Vendor Advisory x_refsource_misc
https://www.westerndigital.com/support/productsecurity/wdc-19012-my-cloud-home-and-ibi-websites-2-2-0
Scores
CVSS v3
4.7
EPSS
0.0089
EPSS Percentile
54.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Details
CWE
CWE-1021
Status
published
Products (2)
westerndigital/ibi
< 2.2.0
westerndigital/my_cloud_home
< 2.2.0
Published
Apr 15, 2020
Tracked Since
Feb 18, 2026