Kerio Connect 8.0.0 through 9.2.2, and Kerio Connect Client desktop application for Windows and Mac 9.2.0 through 9.2.2, when e-mail preview is enabled, allows remote attackers to conduct clickjacking attacks via a crafted e-mail message.
2017-05-02T14:59:00.580
2025-04-20T01:37:25.860
Deferred
CVSSv3.1: 6.5 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gfi | kerio_connect | ≤ 9.2.2 | Yes |
Application | gfi | kerio_connect_client | ≤ 9.2.2 | Yes |
Operating System | apple | macos | - | No |
Operating System | microsoft | windows | - | No |