← back
CVE-2017-16775highCWE-1021

CVE-2017-16775

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.1epss 1.1%
exploitation probability
1.1%top 38% of all CVEs
observed exploitation
nono source reports it
In short

Synology SSO Server fails to properly protect against clickjacking attacks, where attackers can trick users into clicking hidden buttons or links by overlaying fake UI elements on top of legitimate ones.

Technical detail

CWE-1021 vulnerability in SSOOauth.cgi lacks proper frame-busting or X-Frame-Options headers, enabling remote attackers to embed the application in a malicious iframe and perform clickjacking attacks without authentication requirements.

Summary generated and translated by AI from the official description.
Improper restriction of rendered UI layers or frames vulnerability in SSOOauth.cgi in Synology SSO Server before 2.1.3-0129 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Affected products
Synology · SSO Server