An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A UI Redress (or Clickjacking) vulnerability exists. This issue has been resolved by adding a feature that enables Connect administrators to protect users from UI redressing (or clickjacking) attacks.
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with.
Link | Tags |
---|---|
https://helpx.adobe.com/security/products/connect/apsb17-35.html | vendor advisory |
http://www.securitytracker.com/id/1039799 | vdb entry third party advisory |
http://www.securityfocus.com/bid/101838 | vdb entry third party advisory |