Vulnerabilities > CVE-2019-16371 - Improper Restriction of Rendered UI Layers or Frames vulnerability in Logmein Lastpass

047910
CVSS 8.2 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
LOW
Availability impact
NONE
network
low complexity
logmein
CWE-1021

Summary

LogMeIn LastPass before 4.33.0 allows attackers to construct a crafted web site that captures the credentials for a victim's account on a previously visited web site, because do_popupregister can be bypassed via clickjacking.

Vulnerable Configurations

Part Description Count
Application
Logmein
101