CVE-2019-16371: Logmein Lastpass
High severity, CVSS 8.2. EPSS: 1.2% chance of exploitation in the next 30 days.
LogMeIn LastPass before 4.33.0 allows attackers to construct a crafted web site that captures the credentials for a victim's account on a previously visited web site, because do_popupregister can be bypassed via clickjacking.
Affected products
- Logmein Lastpass: before 4.33.0 (fixed in 4.33.0)
Published 2019-09-16. Last modified 2026-06-17.