exponentcms / exponent-cms

Content Management, Simple.
exponentcms.org
GNU General Public License v2.0
60 stars 24 forks source link

Critical Click Jacking Vulnerability In 2.3.1 #1277

Open exponentcms opened 4 years ago

exponentcms commented 4 years ago

Hello Exponent

while looking into your cms i found that its vulnerable to click jacking

by using clickjacking an attacker can directly bypass the referer based csrf protection which will be exploited on victim side

please see the attached screen shot and to know how it can be exploited kindly read my blog post on this same vulnerability -

http://hacktivity.websecgeeks.com/linkedin-clickjacking/

will look forward to you

exponentcms commented 4 years ago

So what your are going to do next ? about this issue !

exponentcms commented 4 years ago

[bulk edit]

exponentcms commented 4 years ago

[bulk edit]

exponentcms commented 4 years ago

[bulk edit]

exponentcms commented 4 years ago

Lighthouse URL: https://exponentcms.lighthouseapp.com/projects/61783/tickets/1233

danielelkabes commented 3 years ago

Hi team, is there any updates on this ?