The web server in the Teradici Managament console versions 20.04 and 20.01.1 did not properly set the X-Frame-Options HTTP header, which could allow an attacker to trick a user into clicking a malicious link via clickjacking.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13174
Reference (s):
- https://advisory.teradici.com/security-advisories/58/
- URL: https://advisory.teradici.com/security-advisories/58/

