Executive brief
Akinsoft LimonDesk, a customer support and help desk software, is vulnerable to clickjacking. This security flaw allows an attacker to trick authorized users into performing unintended actions by overlaying the legitimate interface with a hidden, malicious layer. This could lead to unauthorized configuration changes or data manipulation if an administrative user is successfully targeted.
Technical details
Akinsoft LimonDesk versions s1.02.14 through v1.02.17 contain a clickjacking vulnerability (CWE-1021). The application fails to properly implement security headers such as X-Frame-Options or Content-Security-Policy (CSP) 'frame-ancestors' directives, allowing the UI to be embedded in an unauthorized iframe. An attacker can leverage this to perform an iFrame Overlay attack (CAPEC-103), tricking a high-privileged user into clicking hidden UI elements. Exploitation requires the attacker to convince an authenticated user to visit a malicious webpage. The vulnerability was addressed in version 1.02.17.
Affected products
- Akinsoft LimonDesk s1.02.14 to v1.02.17
Timeline
- 2025-09-03: disclosed
- 2025-09-03: advisory