Clickjacking /framing on sensitive Subdomain
None
Vulnerability Details
Vulnerability Name : Clickjacking /framing
Vulnerability Description : Clickjacking is an interface-based attack in which user is tricked into clicking on actionable content on a hidden website by
clicking on some other content in a decoy website .
Vulnerable Url : https://cryptoeconomics.sifchain.finance/
. Steps to reproduce :
1 - copy the url : https://cryptoeconomics.sifchain.finance/#sif10jatqfd88m8s2uhtdtdl3txtayjtzsve2klyhh&type=lm
2 - Go to test the vulnerability by using : https://www.lookout.net/test/clickjack.html
$ POC :
. Screenshots .
## Impact
The user assumes that they're entering their information into a usual form but they're actually entering it in fields the hacker has overlaid on the UI. Hackers will target passwords, credit card numbers and any other valuable data they can exploit .
Actions
View on HackerOneReport Stats
- Report ID: 1195209
- State: Closed
- Substate: not-applicable