CVE-2024-10454: Clibo Manager

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Clickjacking vulnerability in Clibo Manager v1.1.9.12 in the '/public/login' directory, a login panel. This vulnerability occurs due to the absence of an X-Frame-Options server-side header. An attacker could overlay a transparent iframe to perform click hijacking on victims.

Affected products

Published 2024-10-31. Last modified 2026-06-17.