Security vulnerabilities

  • Status Closed
  • Assigned To
    cbay
  • Private
Attached to Project: Security vulnerabilities
Opened by elit3pwner - 16.08.2024
Last edited by cbay - 17.08.2024

FS#70 - ClickJacking Leads to deletion of user profile

Description: There is clickjacking vulnerability at https://admin.alwaysdata.com/admin/details/ endpoint. And, for deleting a profile, we just need two clicks.

Steps to reproduce:
1) Open your browser and search for https://admin.alwaysdata.com/admin/details/ 2) create an html file that overlays delete this profile icon and then the submit button.

Impact: Admin's account can be deleted in two clicks.

Closed by  cbay
17.08.2024 18:19
Reason for closing:  Invalid
Admin
cbay commented on 17.08.2024 16:54

Hello,

We're already setting the `frame-ancestors` directive in our Content Security Policy to prevent clickjacking.

Kind regards,
Cyril

So, will this issue be a valid one??

Admin
cbay commented on 17.08.2024 18:19

No.

Loading...

Available keyboard shortcuts

Tasklist

Task Details

Task Editing