Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-9361

CSRF protection is vulnerable to UI redressing

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Major
    • 5.2-milestone-1
    • 5.1
    • Security
    • None
    • Unknown
    • N/A
    • N/A

    Description

      The CSRF warning page can be displayed in an IFRAME. That could enable a malicious user to use some UI Redressing attack to perform clickjacking. The CSRF resubmit page shouldn't be allowed to be displayed in an IFrame.

      Attachments

        Activity

          People

            thomas_delafosse Thomas Delafosse
            thomas_delafosse Thomas Delafosse
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: