ClickJacking on Debug
W
Weblate
Submitted None
Actions:
Reported by
bf7e43565d8cf54de3bc5a7
Vulnerability Details
Technical details and impact analysis
#Proof Of Concept:
Related Issue on report #225543
1. Navigate to https://debug.weblate.org
2. As you notice it is forbidden.
3. just vulnerable by clickjacking.
3. Now the user report to CIA to open.
4. Redirect to MaliciousSite.com
I uploaded the poc.html
Thanks,
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
UI Redressing (Clickjacking)