Clickjacking on https://nextcloud.com/

Disclosed: 2019-11-11 15:23:52 By j4tayu To nextcloud
None
Vulnerability Details
the vulnerability is Clickjacking Steps for Reproduce: 1. Create a script like this <title> Clickjacking! </ title> <p> The Site is Vulnerability Clickjacking </ p> <iframe src = "https://www.nextcloud.com" height = "700px" width = "700px"> </ iframe> 2. Enter a file name after saving it in the .html format Then the web is Vuln Clickjacking Sorry bad english (im indonesian) ## Impact By using Clickjacking technique, an attacker hijack's click's meant for one page and route them to another page, most likely for another application, domain, or both.
Actions
View on HackerOne
Report Stats
  • Report ID: 661768
  • State: Closed
  • Substate: duplicate
Share this report