CVE-2024-10454 – Clickjacking vulnerability in Clibo Manager
https://notcve.org/view.php?id=CVE-2024-10454
31 Oct 2024 — Clickjacking vulnerability in Clibo Manager v1.1.9.12 in the '/public/login' directory, a login panel. This vulnerability occurs due to the absence of an X-Frame-Options server-side header. An attacker could overlay a transparent iframe to perform click hijacking on victims. • https://www.incibe.es/en/incibe-cert/notices/aviso/clickjacking-vulnerability-clibo-manager • CWE-1021: Improper Restriction of Rendered UI Layers or Frames •
CVE-2024-9199 – Rate limit vulnerability in Clibo Manager
https://notcve.org/view.php?id=CVE-2024-9199
26 Sep 2024 — Rate limit vulnerability in Clibo Manager v1.1.9.2 that could allow an attacker to send a large number of emails to the victim in a short time, affecting availability and leading to a denial of service (DoS). • https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-clibo-manager • CWE-799: Improper Control of Interaction Frequency •
CVE-2024-9198 – Stored Cross-Site Scripting vulnerability in Clibo Manager
https://notcve.org/view.php?id=CVE-2024-9198
26 Sep 2024 — Vulnerability in Clibo Manager v1.1.9.1 that could allow an attacker to execute an stored Cross-Site Scripting (stored XSS ) by uploading a malicious .svg image in the section: Profile > Profile picture. • https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-clibo-manager • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •