Typecho Clickjacking Vulnerability in v1.2.1

Vulnerability

A clickjacking vulnerability has been identified in Typecho version 1.2.1. This issue occurs on the '/install.php' page, where an attacker can manipulate user interactions by overlaying transparent layers, leading users to unintentionally click on elements of the underlying page.

Impact

Exploitation of this vulnerability allows for clickjacking attacks, where user clicks are hijacked and redirected to another page or application.

Remediation

To mitigate this vulnerability, Typecho users can implement the 'X-Frame-Options' HTTP response header, use the 'frame-ancestors' directive in the Content Security Policy, and add defensive code in the user interface, such as JavaScript-based frame busting.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
0.6
exploitability
7.2
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.