CVE-2018-6909

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/11/2018
Last modified:
24/08/2020

Description

A missing X-Frame-Options header in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application could be used by a remote attacker for clickjacking, as demonstrated by triggering an API page request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rainmachine:rainmachine_web_application:-:*:*:*:*:*:*:*