Clickjack Bug in Website

Disclosed by
ethicalpanther's avatar
ethicalpanther
  • Engagement Contrast Security
  • Disclosed date about 3 years ago
  • Priority P5 Bugcrowd's VRT priority rating
  • Status Informational This vulnerability is seen as an accepted business risk
Summary by ethicalpanther

Due to the bug can button can be changed and trick users by downloading malicious files on the users device without knowing them which can result in huge data loss in the world

Activity
  1. poopy_koala (deactivated)’s avatar
    poopy_koala (deactivated) Customer published the disclosure report

    ()

  2. Tal_Bugcrowd’s avatarbugcrowd logo
    Tal_Bugcrowd sent a message

    ()

  3. Tal_Bugcrowd’s avatarbugcrowd logo
    Tal_Bugcrowd changed the state to Informational

    ()

  4. Tal_Bugcrowd’s avatarbugcrowd logo
    Tal_Bugcrowd updated VRT to Server Security Misconfiguration > Clickjacking > Form Input

    ()

  5. ethicalpanther’s avatar
    ethicalpanther sent a message

    ()

  6. ethicalpanther’s avatar
    ethicalpanther updated the disclosure summary

    ()

  7. ethicalpanther’s avatar
    ethicalpanther requested disclosure

    ()

  8. ethicalpanther’s avatar
    ethicalpanther created the submission

    ()