Automattic / Automattic/Adbusters

Examples of Safe iFrame Busters list incorrectly pictela

Open
#53 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
HTML
Stars
29
Forks
22
PR merge metrics
No merged PRs in 30d

Description

/master/templates/pictela/Pictela_iframeproxy.html is not safe according to Randy Westergren

Reference: https://randywestergren.com/xss-vulnerabilities-in-multiple-iframe-busters-affecting-top-tier-sites/

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with /master/templates/pictela/Pictela_iframeproxy.html and compare its safety status with the linked Randy Westergren reference. Determine how this file is represented in the safe iframe busters list; done means the list no longer incorrectly identifies it as safe, with any relevant checks passing.

Written by the indexing model from the issue text.

Assessment

Tech stack
html
Domain
security
Issue type
Bug
Difficulty
1/5
Estimated time
Under an hour
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.