CVE-2019-16371: High severity logmein lastpass vulnerability
Published Sep 16, 2019
·Updated
LogMeIn LastPass before 4.33.0 allows attackers to construct a crafted web site that captures the credentials for a victim's account on a previously visited web site, because dopopupregister can be bypassed via clickjacking.
Affected Software
1 affected component
LogMeIn Lastpass Chrome<4.33.0
Event History
Sep 16, 2019
CVE Published
via MITRE·05:56 PM
Data Sourced
via MITRE·05:56 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-16371?
CVE-2019-16371 has been classified as a high severity vulnerability due to its potential impact on user security.
2
How do I fix CVE-2019-16371?
To mitigate CVE-2019-16371, users should upgrade to LastPass version 4.33.0 or later.
3
What does CVE-2019-16371 affect?
CVE-2019-16371 affects versions of LogMeIn LastPass prior to 4.33.0 used in Chrome.
4
What vulnerability technique is used in CVE-2019-16371?
CVE-2019-16371 exploits clickjacking techniques to capture user credentials.
5
Who is impacted by CVE-2019-16371?
All users of LogMeIn LastPass versions before 4.33.0 are potentially impacted by CVE-2019-16371.