Threats Tagged 'cwe-1022'
View all threats tagged with 'cwe-1022'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-1022'
Click on any threat for detailed analysis and mitigation recommendations
0 PILOS, a frontend for BigBlueButton, versions from 2.1.0 up to but not including 4.14.1, does not set the Cross-Origin-Opener-Policy header. This allows pages opened with target="_blank" to retain a window.opener reference, enabling reverse tabnabbing attacks where a malicious page can manipulate the original PILOS tab. The issue is fixed in version 4.14.1. Join the discussion | CVE Database V5 | 08/06/2026, 21:51:55 UTC Added: 08/06/2026, 22:13:37 UTC |
0 SAP Fiori (Launchpad) is vulnerable to Reverse Tabnabbing vulnerability due to inadequate external navigation protections for its link (<a>) elements. An attacker with administrative user privileges could exploit this by leveraging compromised or malicious pages. While administrative access is necessary for certain configurations, the attacker does not need the administrative privileges to execute the attack. This could result in unintended manipulation of user sessions or exposure of sensitive information. The issue impacts the confidentiality and integrity of the system, but the availability remains unaffected. Join the discussion | CVE Database V5 | 08/12/2025, 02:05:27 UTC Added: 08/12/2025, 02:32:50 UTC |
0 IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.4 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser. Join the discussion | CVE Database V5 | 07/18/2025, 18:51:05 UTC Added: 07/18/2025, 19:01:12 UTC |
Showing 1 to 3 of 3 results