First published: Mon Sep 16 2019(Updated: )
LogMeIn LastPass before 4.33.0 allows attackers to construct a crafted web site that captures the credentials for a victim's account on a previously visited web site, because do_popupregister can be bypassed via clickjacking.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
LogMeIn LastPass | <4.33.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-16371 has been classified as a high severity vulnerability due to its potential impact on user security.
To mitigate CVE-2019-16371, users should upgrade to LastPass version 4.33.0 or later.
CVE-2019-16371 affects versions of LogMeIn LastPass prior to 4.33.0 used in Chrome.
CVE-2019-16371 exploits clickjacking techniques to capture user credentials.
All users of LogMeIn LastPass versions before 4.33.0 are potentially impacted by CVE-2019-16371.