hackmdio/codimd

<iframe> tag cause open redirect

開放

#959 建立於 2018年9月18日

 (2 則留言) (0 個反應) (0 位負責人)JavaScript (1,038 個分叉)batch import
Hacktoberfesthelp wantedsecurity

倉庫指標

星標
 (8,949 顆星)
PR 合併指標
 (PR 指標待抓取)

描述

If the source website has the script like this:

<script type="text/javascript">
if(window != top) {
    top.location.href = location.href;
}
</script>

It may cause a open redirect issue on codimd. I use www.plurk.com which has anti-clickjacking code to demo.

Demo Link in demo.codimd.org

<iframe src="https://www.plurk.com/k1tten_">

Broswer verison:

Safari 11.0.2: triggered
Firefox Quantum 62.0 : triggered
Chrome 68.0.3440.106: not triggered

貢獻者指南