CVE-2017-7440

Kerio Connect 8.0.0 through 9.2.2, and Kerio Connect Client desktop application for Windows and Mac 9.2.0 through 9.2.2, when e-mail preview is enabled, allows remote attackers to conduct clickjacking attacks via a crafted e-mail message.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gfi:kerio_connect:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:gfi:kerio_connect_client:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-05-02 14:59

Updated : 2024-01-26 18:02


NVD link : CVE-2017-7440

Mitre link : CVE-2017-7440

CVE.ORG link : CVE-2017-7440


JSON object : View

Products Affected

gfi

  • kerio_connect_client
  • kerio_connect

microsoft

  • windows

apple

  • macos
CWE
CWE-1021

Improper Restriction of Rendered UI Layers or Frames