Clickjacking in Legalrobot app

Disclosed: 2017-11-10 11:36:03 By 9it0wl To legalrobot
Unknown
Vulnerability Details
Dear Team, #POC Please find attached screenshots #Steps to reproduce: create index.html file with following content: <iframe sandbox="allow-scripts allow-forms" src="https://app.legalrobot-uat.com/pending-verification" width="1000" height="600"></iframe> Open index.html in browser Actual result: Legalrobot email verification page is viewed in iframe. #Remediation: Frame busting technique is the better framing protection technique. Sending the proper X-Frame-Options HTTP response headers that instruct the browser to not allow raming from other domains. Same issue found in https://app.legalrobot.com/pending-verification as well.
Actions
View on HackerOne
Report Stats
  • Report ID: 270454
  • State: Closed
  • Substate: resolved
  • Upvotes: 8
Share this report