Details
-
Bug
-
Resolution: Fixed
-
Major
-
5.1
-
None
-
Unknown
-
N/A
-
N/A
-
Description
The CSRF warning page can be displayed in an IFRAME. That could enable a malicious user to use some UI Redressing attack to perform clickjacking. The CSRF resubmit page shouldn't be allowed to be displayed in an IFrame.