wathne / dat250-2024-assignment

MIT License
0 stars 0 forks source link

Missing Anti-clickjacking Header #8

Closed LisaCabot closed 2 weeks ago

LisaCabot commented 1 month ago

Description: The page allows for other applications to set another layer on top of the page. Potential Impact: Tricking a user to click on things they are not aware of, or had intent to click. Like an invisible button. Affected part of the application: Frontend, Page design Type of vulnerability: Lack of protection when designing the header (https://cwe.mitre.org/data/definitions/1021.html)

wathne commented 2 weeks ago

Fixed by darunor https://github.com/wathne/dat250-2024-assignment/commit/21bbf8911b23d21b4c12306e524bb8fb33e91903