Vulnerability Description
BCN Quark Quarking Password Manager 3.1.84 suffers from a clickjacking vulnerability caused by allowing * within web_accessible_resources. An attacker can take advantage of this vulnerability and cause significant harm.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bcnquark | Quarking Password Manager | 3.1.84 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/153405/Quarking-Password-Manager-3.1.84-Cli
- http://seclists.org/fulldisclosure/2019/Jun/31Mailing ListThird Party Advisory
- https://chrome.google.com/webstore/detail/quarking-password-manager/gfkmpfajamepProductVendor Advisory
- http://packetstormsecurity.com/files/153405/Quarking-Password-Manager-3.1.84-Cli
- http://seclists.org/fulldisclosure/2019/Jun/31Mailing ListThird Party Advisory
- https://chrome.google.com/webstore/detail/quarking-password-manager/gfkmpfajamepProductVendor Advisory
FAQ
What is CVE-2019-12880?
CVE-2019-12880 is a vulnerability with a CVSS score of 4.3 (MEDIUM). BCN Quark Quarking Password Manager 3.1.84 suffers from a clickjacking vulnerability caused by allowing * within web_accessible_resources. An attacker can take advantage of this vulnerability and caus...
How severe is CVE-2019-12880?
CVE-2019-12880 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-12880?
Check the references section above for vendor advisories and patch information. Affected products include: Bcnquark Quarking Password Manager.