Improper Restriction of Rendered UI Layers or Frames in eSOMS - CVE-2019-19001
Published: March 13, 2020
eSOMS
ABB
Description
The vulnerability allows a remote attacker to gain access to sensitive information on the target system.
The vulnerability exists due to the X-Frame-Options header is not configured in HTTP response. A remote attacker can perform a "ClickJacking" attack and frame parts of the application on a malicious website, revealing sensitive user information such as authentication credentials.