VDB

CVE-2021-3731

CVE-2021-3731 PUBLISHED CVSS 5.900000095367432 MEDIUM

LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable to 'clickjacking'. This allows an attacker to trick a targetted user to execute unintended actions.

EPSS 1.24% · 66.6th percentile

Risk Scores

CVSS 3.1
5.900000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
EPSS Score
1.24%
66.6th percentile

Affected Products

VendorProductVersions
ledgersmbledgersmb1.1.0, 1.2.0, 1.4.0
ledgersmbledgersmb/ledgersmb1.7.33, unspecified
debiandebian_linux10.0, 11.0

Timeline

  • Aug 23, 2021 CVE Published
  • Aug 24, 2021 EPSS Score
  • Oct 21, 2021 EPSS Score
  • Dec 19, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Apr 15, 2022 EPSS Score
  • Jun 12, 2022 EPSS Score
  • Aug 11, 2022 EPSS Score
  • Oct 8, 2022 EPSS Score
  • Dec 6, 2022 EPSS Score
  • Feb 2, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›