Single Sing On - Clickjacking

Disclosed: 2018-02-21 15:27:13 By r0p3 To semrush
Low
Vulnerability Details
**Description:** Clickjacking (User Interface redress attack, UI redress attack, UI redressing) is a malicious technique of tricking a Web user into clicking on something different from what the user perceives they are clicking on. **Browsers Verified In:** Any **Steps To Reproduce:** Create HTML file containg following code: ` <iframe src="https://sso.semrush.com/"></iframe> ` Execute the HTML file & you will see Single Sing On login page present trough the iframe. **Supporting Material/References:** ## Impact Revealing confidential information(credentials) AND/OR taking control of their computer/account while clicking on seemingly innocuous web pages.
Actions
View on HackerOne
Report Stats
  • Report ID: 299009
  • State: Closed
  • Substate: resolved
  • Upvotes: 11
Share this report