clickjacking attack in notrinos/notrinoserp


Reported on

Aug 21st 2022


clickjacking bug.
I see there is no x-frame-options header set . So, the erp url can be loaded in iframe tag . which allow clickjacking attack

Proof of Concept

same this bellow code in html file and open this html url is browser .

<iframe src="http://localhost/notrinoserp/index.php?application=system"></iframe>

similar report


clickjacking attack

We are processing your report and will contact the notrinos/notrinoserp team within 24 hours. a month ago
We have contacted a member of the notrinos/notrinoserp team and are waiting to hear back a month ago
Phương gave praise a month ago
Thanks @ranjit-git for detecting this vulnerability, it will be fixed soon.
The researcher's credibility has slightly increased as a result of the maintainer's thanks: +1
Phương validated this vulnerability a month ago
ranjit-git has been awarded the disclosure bounty
The fix bounty is now up for grabs
The researcher's credibility has increased: +7
Phương confirmed that a fix has been merged on c2ff3d a month ago
Phương has been awarded the fix bounty
to join this conversation