sandboxed-iframes

1 article
sort: new top best
clear filter
0 7/10

A clickjacking vulnerability in Microsoft Yammer was discovered by exploiting HTML5 sandboxed iframes to bypass the application's frame-busting JavaScript protections, allowing attackers to iframe sensitive pages and perform unauthorized actions on behalf of logged-in users. Microsoft patched the issue by implementing X-Frame-Options: SAMEORIGIN header.

Microsoft Yammer Seekurity Mohamed A. Baset
seekurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details