missing-security-headers

1 article
sort: new top best
clear filter
0 6/10

A clickjacking vulnerability in Facebook's AJAX endpoint (/ajax/home/generic.php) allowed attackers to iframe a resource lacking X-Frame-Options headers and submit forms to trick victims into adding the attacker to secret groups or performing other unwanted actions on Facebook resources.

Facebook Mohamed A. Baset Seekurity
seekurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 11 hours ago · details