CVE-2019-9147

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/07/2019
Last modified:
24/08/2020

Description

Mailvelope prior to 3.1.0 is vulnerable to a clickjacking attack against the settings page. As the settings page is intended to be accessible from web applications, the browser's extension isolation mechanisms are disabled (web_accessible_resources). Mailvelope implements additional measures to prevent web applications from directly embedding the settings page, but this mechanism can be bypassed.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mailvelope:mailvelope:*:*:*:*:*:*:*:* 3.1.0 (excluding)