GHSA-g26h-g3h8-pq5x
GitHub Security Advisory
⚠ Unreviewed
MODERATE
Has CVE
Advisory Details
For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially allow 'ClickJacking' attacks where an attacker can frame parts of the application on a malicious web site, revealing sensitive user information such as authentication credentials.
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: June 28, 2025 6:27 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.