Loading HuntDB...

Frameset(Frame) html tag is allowed in html editor.(can lead to clickjacking)

Low
K
Khan Academy
Submitted None
Reported by na5ne3t

Vulnerability Details

Technical details and impact analysis

UI Redressing (Clickjacking)
Hello Sir/Mam , I was using the html editor in computer programming section , which allowed me to design a webpage. When i use the iframe tag , object tag and embed tag it show me the message that these tags are not allowed for security reasons(may be cause of clickjacking attack or something) but when i used frameset n frame tag it does not showed any message and allows them. The X-frame option is set to same-origin. So, it allowed to load the user setting page in a frameset tag , (i also recorded the video too)which can lead to clickjacking attack. If there is restriction on iframe , object n embed tag then there should also be restriction on frameset(frame). P.S:The poc video is also attached below.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

UI Redressing (Clickjacking)