Description
Thinfinity VNC v4.0.0.1 contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can trick a user into browse malicious site, to obtain an 'ID' that can be used to send websocket requests and achieve RCE.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-29926 | Thinfinity VNC v4.0.0.1 contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can trick a user into browse malicious site, to obtain an 'ID' that can be used to send websocket requests and achieve RCE. |
References
| Link | Providers |
|---|---|
| https://fluidattacks.com/advisories/clapton/ |
|
History
No history.
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2024-08-03T04:36:06.591Z
Reserved: 2022-02-15T00:00:00.000Z
Link: CVE-2022-25227
No data.
Status : Modified
Published: 2022-05-20T12:15:10.930
Modified: 2024-11-21T06:51:50.500
Link: CVE-2022-25227
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD