CVE-2023-38873
Last modified
CVE-2023-38873 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer is vulnerable to Clickjacking. Clickjacking, also known as a "UI redress attack", is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they were intending to click on the top-level page. EPSS estimates a 0.63% chance of exploitation in the next 30 days.
Description
The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer is vulnerable to Clickjacking. Clickjacking, also known as a "UI redress attack", is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they were intending to click on the top-level page. Thus, the attacker is "hijacking" clicks meant for their page and routing them to another page, most likely owned by another application, domain, or both.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Economizzer | Economizzer | 0.9 | Beta1 |
| Economizzer | Economizzer | april_2023 | — |
References
- https://github.com/dub-flow/vulnerability-research/tree/main/CVE-2023-38873Exploit, Third Party Advisory
- https://www.economizzer.orgProduct
- https://github.com/dub-flow/vulnerability-research/tree/main/CVE-2023-38873Exploit, Third Party Advisory
- https://www.economizzer.orgProduct
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-38873?
How severe is CVE-2023-38873?
How do I fix CVE-2023-38873?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-38865COMFAST CF-XR11 V2.7.2 has a command injection vulnerability…9.8
- CVE-2023-38866COMFAST CF-XR11 V2.7.2 has a command injection vulnerability…9.8
- CVE-2023-3887A vulnerability was found in Campcodes Beauty Salon Manageme…6.1
- CVE-2023-38870A SQL injection vulnerability exists in gugoan Economizzer c…9.8
- CVE-2023-38871The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Ec…5.3
- CVE-2023-38872An Insecure Direct Object Reference (IDOR) vulnerability in …3.7
- CVE-2023-38874A remote code execution (RCE) vulnerability via an insecure …8.8
- CVE-2023-38875A reflected cross-site scripting (XSS) vulnerability in msaa…6.1
- CVE-2023-38876A reflected cross-site scripting (XSS) vulnerability in msaa…6.1
- CVE-2023-38877A host header injection vulnerability exists in gugoan's Eco…8.8
- CVE-2023-38878A reflected cross-site scripting (XSS) vulnerability in DevC…6.1
- CVE-2023-38879The Community Edition version 9.0 of OS4ED's openSIS Classic…7.5
Are you affected by CVE-2023-38873?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
