missing-x-frame-options

1 article
sort: new top best
clear filter
0 6/10

A researcher achieved account takeover by combining clickjacking (missing X-Frame-Options header) with parameter manipulation to trick users into changing their account email. The attacker loaded the profile change page in an invisible iframe and overlaid a fake button to intercept clicks, allowing email hijacking without user consent.

Osama Avvan Bugcrowd
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details