Vulnerabilities > CVE-2019-9147 - Improper Restriction of Rendered UI Layers or Frames vulnerability in Mailvelope

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
low complexity
mailvelope
CWE-1021

Summary

Mailvelope prior to 3.1.0 is vulnerable to a clickjacking attack against the settings page. As the settings page is intended to be accessible from web applications, the browser's extension isolation mechanisms are disabled (web_accessible_resources). Mailvelope implements additional measures to prevent web applications from directly embedding the settings page, but this mechanism can be bypassed.

Vulnerable Configurations

Part Description Count
Application
Mailvelope
76