hackmdio/codimd

<iframe> tag cause open redirect

Open

#959 opened on 2018年9月18日

GitHub で見る
 (2 comments) (0 reactions) (0 assignees)JavaScript (8,949 stars) (1,038 forks)batch import
Hacktoberfesthelp wantedsecurity

説明

If the source website has the script like this:

<script type="text/javascript">
if(window != top) {
    top.location.href = location.href;
}
</script>

It may cause a open redirect issue on codimd. I use www.plurk.com which has anti-clickjacking code to demo.

Demo Link in demo.codimd.org

<iframe src="https://www.plurk.com/k1tten_">

Broswer verison:

Safari 11.0.2: triggered
Firefox Quantum 62.0 : triggered
Chrome 68.0.3440.106: not triggered

コントリビューターガイド

<iframe> tag cause open redirect · hackmdio/codimd#959 | Good First Issue