Description
The web application is vulnerable to a so-called ‘clickjacking’ attack. In this type of attack, the vulnerable page is inserted into a page controlled by the attacker in order to deceive the victim. This deception can range from making the victim click on a button to making them enter their login credentials in a form that, a priori, appears legitimate.
Problem types
CWE-1021 Improper Restriction of Rendered UI Layers or Frames
Product status
1.0.14 (Firmware)
Credits
Víctor Bello Cuevas
Aarón Flecha Menéndez
Iván Alonso Álvarez
References
circutor.com/...ion/conversores-y-pasarelas/product/D80010./
www.hackrtu.com/blog/cg-0day-en-003/