CVE-2011-0399
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/01/2011
Last modified:
11/04/2025
Description
Piwik before 1.1 does not prevent the rendering of the login form inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.
Impact
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:matomo:matomo:*:*:*:*:*:*:*:* | 1.0 (including) | |
cpe:2.3:a:matomo:matomo:0.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:matomo:matomo:0.1.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:matomo:matomo:0.1.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:matomo:matomo:0.1.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:matomo:matomo:0.1.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:matomo:matomo:0.1.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:matomo:matomo:0.1.6:*:*:*:*:*:*:* | ||
cpe:2.3:a:matomo:matomo:0.1.7:*:*:*:*:*:*:* | ||
cpe:2.3:a:matomo:matomo:0.1.8:*:*:*:*:*:*:* | ||
cpe:2.3:a:matomo:matomo:0.1.9:*:*:*:*:*:*:* | ||
cpe:2.3:a:matomo:matomo:0.1.10:*:*:*:*:*:*:* | ||
cpe:2.3:a:matomo:matomo:0.2.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:matomo:matomo:0.2.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:matomo:matomo:0.2.3:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://dev.piwik.org/trac/ticket/1679
- http://osvdb.org/70383
- http://piwik.org/blog/2011/01/piwik-1-1-2/
- http://www.securityfocus.com/bid/45787
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64640
- http://dev.piwik.org/trac/ticket/1679
- http://osvdb.org/70383
- http://piwik.org/blog/2011/01/piwik-1-1-2/
- http://www.securityfocus.com/bid/45787
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64640